Nearly nine million airport customers have had personal information accessed after a cyber security incident at three major UK airports, Manchester Airports Group (MAG) has said.
What happened
MAG, the operator of Manchester, East Midlands and London Stansted, confirmed criminal actors gained access to a system over the recent weekend and extracted data for roughly 8.7 million customers. The company said the attackers demanded a ransom for the return of the information, a demand MAG said it refused to pay. The size of the ransom request has not been disclosed.
MAG stressed that the compromised system did not contain customers' bank or payment details and that, at no point, passenger or aviation security had been affected.
Data taken and immediate effects
The bulk of the material taken related to email addresses collected through terminal Wi‑Fi sign‑ups. MAG said other items accessed included contact details, vehicle registrations and postcodes. The group apologised to passengers for any inconvenience or concern caused and said it takes the security of customer information "extremely seriously".
"We would like to reassure customers that Manchester Airport Group takes the security of customer information extremely seriously and we apologise for any inconvenience or concern caused."
- Airports affected: Manchester, East Midlands, London Stansted (all operated by MAG)
- People affected: about 8.7 million customers
- Data accessed: mainly email addresses from Wi‑Fi registrations, plus contact details, vehicle registrations and postcodes
- Payment details: MAG said none were stored on the system that was accessed
- Ransom: demanded by hackers; MAG refused to pay; amount undisclosed
| Item | Detail |
|---|---|
| Number of customers affected | ~8.7 million |
| Primary data types | Emails (Wi‑Fi sign‑ups); contact details; vehicle registrations; postcodes |
| Financial data | Not stored on hacked system, according to MAG |
Wider implications
The incident underlines ongoing vulnerabilities for companies operating public infrastructure where free Wi‑Fi and customer services collect personal information. Millions of affected customers now face a heightened risk of phishing, targeted scams and identity misuse if the data is circulated or published.
MAG's statement that aviation security was never compromised seeks to reassure passengers, but operators and regulators will now be under pressure to set out how they will strengthen cyber defences, review vendor arrangements and tighten oversight of systems that collect customer data.
It is not yet clear whether the incident will trigger investigations by the Information Commissioner's Office or lead to formal regulatory action. The ICO has in the past pursued enforcement where organisations failed to protect personal data; any such step would depend on the findings of probe into MAG's security controls and the nature of the breach.
What passengers should do
MAG has apologised and urged calm while it investigates. Passengers whose details were taken should be alert to suspicious messages and consider the usual precautions: do not click unexpected links, confirm requests for personal information directly with known contacts, and report suspicious communications to the relevant service provider.
The scale of the data accessed makes follow‑on fraud a realistic risk, particularly where email addresses are used by criminals as a starting point for targeted scams. Customers who used airport Wi‑Fi recently and provided contact information will want to review their account security settings and remain vigilant.
The incident will be closely watched by ministers, transport regulators and other airport operators amid growing concern about the resilience of critical services to cyber crime. MAG has said it is co‑operating with law enforcement as it continues its investigation.
Further updates are expected as enquiries progress and as MAG provides more detail on how the breach occurred and what measures it is taking to protect affected customers.