Manchester Airports Group (MAG), which runs Manchester, Stansted and East Midlands airports, has confirmed that someone gained unauthorised access to customer data. Press reports put the number of affected customers at about 8.7 million, and the breach notification service Have I Been Pwned now lists 8.8 million accounts. The good news, according to MAG, is that bank details and payment information were not accessed.
What happened
In a statement dated 27 August 2026, MAG confirmed unauthorised access to customer data linked to its three airports. The company said the data involved email addresses, phone numbers, vehicle registrations and postcodes. These are the kinds of details people hand over when they book airport parking, reserve a lounge or sign up for airport Wi-Fi.
MAG also said: “Manchester Airport Group takes the security of customer information extremely seriously and we apologise for any inconvenience or concern caused.”
MAG has not said how the attackers got in, and I will not guess.
On the scale, there are two numbers in circulation. Press reports, including coverage by Bitdefender and IT Security Guru, say about 8.7 million customers were affected. Have I Been Pwned, the free service that lets people check whether their email appears in known breaches, added the MAG breach on 2 September 2026 and counts 8.8 million accounts. The two figures are close, and either way this is a very large set of records.
Have I Been Pwned also notes that “The FulcrumSec hacking group later claimed responsibility”. That is a claim by the group, as recorded by the service. MAG has not confirmed it, and its own statement does not name any attacker.
Who is affected
Anyone who has shared details with Manchester, Stansted or East Midlands airports through their online services could be in this data. That includes people who booked parking, lounges or other extras, and people who registered for Wi-Fi.
This matters for readers in our region. Manchester and Stansted are familiar airports for many travellers from the Gulf and the wider Arab world, whether they are visiting family, studying or travelling for work. If you have booked parking or a lounge there, it is worth assuming your email and phone number may be exposed.
The data does not include card or bank details, according to MAG. But a real email address combined with a real car registration and postcode is enough to make a fake message look convincing.
By the numbers
| Item | Detail | Source |
|---|---|---|
| Company | Manchester Airports Group (MAG) | MAG |
| Airports covered | Manchester, Stansted, East Midlands | MAG |
| MAG statement date | 27 August 2026 | MAG |
| Customers affected (press reports) | About 8.7 million | Bitdefender |
| Accounts listed by Have I Been Pwned | 8.8 million | Have I Been Pwned |
| Added to Have I Been Pwned | 2 September 2026 | Have I Been Pwned |
| Data exposed | Email addresses, phone numbers, vehicle registrations, postcodes | MAG |
| Bank and payment details | Not accessed | MAG |
| Responsibility claim | FulcrumSec, not confirmed by MAG | Have I Been Pwned |
What to do now
These steps come from Have I Been Pwned and Bitdefender’s guidance on the breach.
- Check your email address at haveibeenpwned.com to see whether it appears in the MAG breach.
- Treat any unexpected message about parking, lounge or Fast Track bookings as suspect, even if it quotes your real car registration. Go to the official airport website yourself to check a booking.
- Never give a password or card details in reply to such a message, whether it arrives by email, SMS or phone.
- Use a unique password for each travel account and turn on multi-factor authentication wherever it is offered.
My own habit after a breach like this: I save the airport’s official website as a bookmark, and I only ever reach it that way.
Why it matters
No payment data was taken, according to MAG, and that is a real relief. But I think the bigger risk here is quieter. Criminals now potentially hold a list that ties email addresses and phone numbers to real car registrations and to the fact that these people travel through specific airports.
That is ideal material for targeted phishing. A message that says “your parking booking at Manchester needs confirming” and quotes your actual registration will fool far more people than a generic scam. Expect those messages, especially before holiday seasons, and treat them with suspicion.
What caught my attention is how ordinary the data is. Nobody thinks twice about typing a postcode into a parking form or an email into a Wi-Fi page. This breach is a reminder that every form we fill in becomes part of someone’s database, and that database becomes a target.
Sources
- Manchester Airports Group, statement on cyber security incident, 27 August 2026, https://mediacentre.magairports.com/mag-statement-on-cyber-security-incident/
- Have I Been Pwned, breach entry for Manchester Airports Group, added 2 September 2026, https://haveibeenpwned.com/Breach/ManchesterAirportsGroup
- Bitdefender, report and guidance on the Manchester Airports Group data breach affecting 8.7 million customers, 2026, https://www.bitdefender.com/en-us/blog/hotforsecurity/manchester-airports-group-data-breach-8-7-million