Manchester Airports Group data breach: 8.7 million customer records accessed
If you are a customer of Manchester Airports Group, here’s what is being claimed, and what it would mean for you.
Manchester Airports Group has confirmed that an unauthorised party accessed customer data from airport Wi-Fi sign-ups and from car-park, lounge and Fast Track bookings at Manchester, London Stansted and East Midlands airports. MAG told journalists about 8.7 million customers were involved, mostly Wi-Fi email addresses, and that no bank or payment details were held in the system. The stolen copy cannot be taken back; the live risk is convincing airport-themed scam messages, not a drained account.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
On 27 August 2026, Manchester Airports Group (MAG) — which operates Manchester, London Stansted and East Midlands airports — confirmed a cyber security incident. MAG said it became aware on Tuesday 25 August 2026, and that an unauthorised third party had obtained customer data a few days earlier, over the preceding weekend. MAG told journalists the figure was about 8.7 million customers, and that the vast majority of records were email addresses from in-airport Wi-Fi sign-ups.
Watch Manchester Airports Group
Get alerted the next time Manchester Airports Group files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Manchester Airports Group’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals — $499/mo or $4,990/yr (indicative estimate).
The data related to car-park, lounge and Fast Track bookings as well as those Wi-Fi sign-ups. MAG said it included email addresses, phone numbers, vehicle registrations and postcodes, and that neither MAG nor the accessed system held customers’ bank or payment details. MAG said it contained the risk, refused a ransom demand, and that passenger safety, aviation security and airport operations were never compromised. Bookings remain valid. The UK data regulator, the ICO, confirmed it received MAG’s breach report and is assessing it.
No payment details were taken. That is not the same as an empty file
Almost every report has led with MAG’s reassurance: no bank details, airports still running, flights and safety never at risk. MAG has said all of that, and nothing in the public record contradicts it. If the question you actually have is “can someone now spend my money because I parked at Stansted or used the Wi-Fi?”, the honest answer from what MAG has confirmed is no.
Here is what that framing skips. MAG’s own figure of about 8.7 million is not mainly people who paid for parking, a lounge or Fast Track. MAG told the BBC the vast majority of records were emails collected when people signed up for airport Wi-Fi. Typing an email into a free Wi-Fi screen at one of those three airports was enough. You may never have thought of yourself as a MAG customer, and you may not be watching for mail from an airport group at all.
What MAG says the attackers hold is still a working kit: email addresses, phone numbers, vehicle registrations and postcodes, sitting next to airport bookings and Wi-Fi sign-ups. A registration plate and a postcode, plus a phone number or email, is enough for a message to feel as if it comes from the airport — a parking charge, a Fast Track problem, a “manage your booking” link. MAG said it knows who did this but has not named them, and it said it refused to pay. Refusing a ransom is not the same as getting the copy back. MAG has not said the data has been published or sold; that remains unconfirmed. It also cannot be deleted from the people who took it.
The honest read is not “your card is about to be used”. It is a large, travel-linked contact list. People with parking, lounge or Fast Track records have the richer file, and should expect more specific follow-up scams. The much larger Wi-Fi group mainly have an email sitting in a stolen airport list. In both cases MAG has been contacting people, which means genuine notices and fakes will now arrive in the same inboxes.
What to actually expect
- MAG has been emailing affected customers. You may get a genuine message, a fake one, or both. Do not use links or attachments in unexpected mail or texts to “log in”, “claim compensation”, or “see whether you were involved”. MAG posted a public statement on the London Stansted Airport website; if you want MAG’s words, go to the official airport site yourself by typing it in.
- The near-term nuisance is not a drained bank account. It is emails, texts or calls about parking, Fast Track, lounges, Wi-Fi, or “your data from the airport breach”. Anyone who asks you to pay a fee, confirm a card, or share a password is not MAG clearing this up. MAG has said payment details were not in the system that was accessed.
- Your existing car-park, lounge and Fast Track bookings remain valid. MAG temporarily suspended the online “Manage My Booking” service as a precaution. That was a lock-down choice. MAG said airport operations were not disrupted.
- There is no confirmed public leak or sale in MAG’s statement or in the reporting that followed it. MAG refused the ransom, so a later dump is possible — it has not been confirmed. The ICO is assessing MAG’s report. That process does not retrieve the stolen copy.
What you can and cannot fix
The copy allegedly taken from MAG cannot be recalled. If your email address, phone number, vehicle registration or postcode was in the accessed data, that copy is out. MAG’s apology, the ICO’s assessment, and MAG’s refusal to pay do not put it back. Nobody can honestly promise to remove it from the people who already have it.
A vehicle registration is particularly sticky. You are unlikely to change it because of this, and a scammer who has it knows it still belongs to a real car. A postcode is not your full home address, but it does not expire either. Changing an email address later does not unsay the old one.
- Treat airport, parking, lounge and Fast Track messages as untrusted until you have opened the official airport website yourself. That is the highest-value step, because the stolen fields are exactly what makes a fake “airport” message look real.
- Do not pay anyone, confirm a card, or hand over a password “because of the MAG breach”. MAG has said the accessed system did not hold bank or payment details. A request for those is the scam, not the cleanup.
- Be extra sceptical of anything that quotes a vehicle registration — fake parking charges, unpaid-stay texts, penalty notices. The plate is one of the few details MAG has confirmed was in this incident, and you cannot usefully take it back.
- If you want a lever that actually moves, it is not the MAG file. It is the people-search listings that already publish names next to old addresses, relatives, phone numbers and employers. A bare leaked email, phone number or postcode becomes much more useful to a stranger once it can be joined to those pages. Unlike the stolen MAG copy, those listings can often be opted out of. Reducing that wider public footprint is the part you still control.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
ADT 5.5–10 Million Customer Records Disclosed — April 2026
ADT confirmed unauthorized access to between 5.5 and 10 million customer records in April 2026. Expo…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…
Under Armour 72M Customer Email Dataset Resurfaces — January 2026
72 million user emails from a prior Under Armour breach were reposted publicly in January 2026, ampl…