Manchester Airports Group (MAG) has confirmed that an unauthorised third party accessed a quantity of customer data in a cybersecurity incident affecting three UK airports. The breach involved information linked to car park, lounge and Fast Track bookings and to in‑airport Wi‑Fi registrations at Manchester Airport, London Stansted Airport and East Midlands Airport.
UK airports cyber attack: scope of data accessed
MAG said the compromised information includes customer email addresses, phone numbers, vehicle registration numbers and postcodes. The airport operator stressed that bank and payment details were not exposed, saying “Neither MAG nor the system accessed hold customers’ bank or payment details.”
MAG said it moved quickly to contain the incident, has immediately contained the risk and is working with specialist advisers and the relevant authorities. The company said it has informed the relevant authorities and is cooperating with them as the incident is addressed, and that it is taking steps to protect customers and its systems. MAG also apologised to customers for any concern or inconvenience caused and added that it “takes the security of customer information extremely seriously.”
Despite the cybersecurity breach, MAG said there has been no impact on passenger safety or aviation security: “At no point has passenger safety or aviation security been compromised.” The incident has not caused operational disruption at the three airports, with MAG stating that “airport operations remain unaffected and customer parking services continue to operate normally.”
The three airports collectively handle tens of millions of passengers each year: Manchester Airport recorded more than 32 million travellers over the past 12 months, Stansted Airport handled more than 30 million passengers, and East Midlands Airport recorded around 4 million passengers during the same period, according to figures cited.

