What Happened
Manchester Airports Group (MAG), the UK's largest airport operator, has confirmed that hackers breached its systems and stole customer data tied to car park, lounge, and Fast Track bookings. MAG operates three airports — Manchester Airport, London Stansted Airport, and East Midlands Airport — which together serve more than 66 million passengers a year.
What Was Exposed
| Data Type | Exposed |
|---|---|
| Email addresses | Yes |
| Phone numbers | Yes |
| Vehicle registration numbers | Yes |
| Postcodes | Yes |
| Payment card data | No — not accessed |
The compromised data relates specifically to car park, lounge, and Fast Track bookings rather than flight or passport records. MAG has not published an official figure for how many customers were affected, but local media reports — citing private company statements — put the number as high as 8.9 million travelers.
Company Response
MAG says it moved to contain the incident by:
- Restricting system access to stop further unauthorized activity
- Engaging external cybersecurity experts to investigate
- Notifying law enforcement
- Temporarily suspending its online "Manage My Booking" service, directing affected customers to phone support instead
- Contacting impacted individuals directly and advising them to watch for suspicious follow-up communications (phishing, smishing, or vishing attempts using the leaked contact details)
No ransomware or data-extortion group has publicly claimed responsibility for the breach as of this writing.
Why This Matters
Even without payment card or passport data, the exposed fields — email, phone number, vehicle plate, and postcode — are a ready-made kit for targeted phishing and vehicle-based social engineering against travelers who used MAG's premium airport services. Customers of Manchester, Stansted, or East Midlands airports who booked parking, a lounge, or Fast Track access should treat unsolicited emails or calls referencing those bookings with suspicion, and verify any request for further personal or payment information directly through MAG's official channels.
Recommended Actions for Affected Travelers
- Be alert for phishing — MAG will not ask for passwords or full card details by email or phone following this incident.
- Verify unexpected contact — confirm any booking-related message through MAG's official site or phone line before clicking links or replying.
- Watch for vehicle-related scams — exposed registration numbers and postcodes can be used to craft convincing parking-fine or towing scams.
- Use phone support while the online Manage My Booking portal remains suspended.