Nearly nine million passengers have had their personal data accessed in a cyber-attack targeting three major UK airports operated by Manchester Airports Group (MAG). The breach, which occurred over the past weekend and was detected on Tuesday, affected Manchester Airport, London Stansted, and East Midlands Airport.
MAG confirmed that the compromised information includes customer email addresses, phone numbers, vehicle registration numbers, and postcodes linked to car park, lounge, fast-track bookings, and in-airport Wi-Fi sign-ups. Company officials emphasized that no bank or payment details, passwords, addresses, or passport information were accessed. Airport operations were not disrupted by the incident, and passenger safety and aviation security were not compromised.
Following detection of suspicious activity, MAG took immediate steps to contain the breach, suspending access to its online booking system as a precaution and advising customers to contact the airports by phone for any booking changes. All affected passengers have reportedly been contacted, with the company warning them to remain vigilant against potential phishing attempts and other fraudulent communications. In a statement to customers, MAG stressed it would never request payment or banking information unexpectedly.
The group behind the cyber-attack reportedly demanded a ransom of £5 million to return the stolen data, setting a 48-hour deadline for payment. MAG declined to pay the ransom, leaving the attackers free to sell the data on underground markets. Investigators have not confirmed the identity or origin of the hackers but described the group as "well-known" and noted the ransom demand was relatively low compared to other recent cyber extortion cases. Analysts described the attack as sophisticated, involving methods beyond simple phishing or standard tactics.
National authorities, including the UK’s National Cyber Security Centre (NCSC) and the Information Commissioner’s Office (ICO), have been notified and are working with MAG to respond to the incident. The NCSC has urged affected individuals to be cautious with emails, calls, and texts that may attempt to exploit the breach.
Experts in cybersecurity have highlighted the risks associated with large volumes of personal data, even when financial details are not involved. Beverley Griffiths, a security and resilience lecturer, noted that combined information—such as email addresses, phone numbers, and vehicle registrations—can be used to create detailed individual profiles, potentially facilitating targeted phishing, social engineering, and fraud.
The breach comes amid heightened concerns over the vulnerability of critical infrastructure to cyber-attacks. Last year, cyber incidents affected several UK and European airports, causing delays and cancellations, while recent attacks have targeted energy and industrial sectors.
Manchester, Stansted, and East Midlands airports collectively handled approximately 66 million passengers last year, underscoring the scale of the potential impact. MAG has reiterated its commitment to safeguarding customer information and apologized for any inconvenience or concern caused by the incident.
