
Manchester Airports Group (MAG), the UK’s largest airport operator, has disclosed a significant data security incident that compromised the personal information of 8.7 million people.
Manchester Airports Group (MAG) is the UK’s largest airport operator and one of the country’s leading aviation groups. It owns and operates Manchester Airport, London Stansted Airport and East Midlands Airport, serving millions of passengers each year.
On August 27, in a data security notice published on its website, MAG said that it recently was a victim of a data security incident where threat actors gained unauthorised access to its internal network. The company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
While the full details of the incident are yet to be shared, MAG said that a quantity of customer data relating to car park, lounge and Fast Track bookings, as well as in-airport Wi-Fi sign-ups, was obtained at Manchester, Stansted and East Midlands airports.
The company said the incident had not compromised passenger safety or aviation security and had caused no disruption to airport operations. It added that all airport services remain operational, with customer parking facilities continuing to function as normal.
“We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems. We have informed and are working with the relevant authorities,” MAG said.
MAG confirmed that neither the group nor the affected system stored customers’ banking or payment information, meaning such financial details were not compromised in the incident. The company said the information accessed included customers’ email addresses, phone numbers, vehicle registration numbers and postcodes.
While MAG did not initially disclose the number of individuals affected, a company spokesperson told The Register that the group had identified up to 8.7 million customers whose data may have been impacted by the incident. MAG cautioned that the figure could rise as its investigation into the breach continues.
The UK Information Commissioner’s Office (ICO) said that MAG had formally notified the regulator about the incident. The ICO said it was currently assessing the situation and would consider the circumstances surrounding the data security incident, including the nature and extent of the information involved, before determining whether any further action was necessary.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543