Manchester Airport Hack Exposes Data of 8.7 Million Travelers

A cyberattack on Manchester Airports Group exposed emails, phone numbers and vehicle data of 8.7 million travelers, many bound for India.

Aug 31, 2026 - 07:11
Aug 31, 2026 - 10:13
5 min read
 0
Manchester Airport Hack Exposes Data of 8.7 Million Travelers

Three of England's busiest airports just told 8.7 million people that someone else had been sitting inside their customer databases. No flights were grounded and no bank cards were touched — but that's cold comfort if your phone number, car registration and home postcode are now sitting on a hacker's hard drive.

What Manchester Airports Group actually lost

Manchester Airports Group (MAG), which runs Manchester Airport, London Stansted and East Midlands Airport, confirmed on August 27 that an "unauthorised third party" — company-speak for an outside attacker who broke in without permission — had accessed systems tied to car park bookings, airport lounge access, Fast Track security passes, and WiFi sign-ups across all three airports. Fast Track, for anyone unfamiliar, is the paid service that lets travelers skip the regular security queue.

The data exposed includes email addresses, phone numbers, vehicle registration numbers and postcodes. MAG has been clear about what wasn't touched: no bank details, no payment card numbers, and — crucially — nothing that compromised passenger safety or the actual operation of the airports. Roughly 8.7 million customer records were caught up in it, though MAG hasn't said how long the intruder was inside before anyone noticed.

The weak link was something almost everyone signs up for without thinking

A lot of the exposed records trace back to airport WiFi registration — the login screen that asks for your email and phone number before letting you online, technically called a captive portal. It's the kind of form millions of people fill in on autopilot while waiting for a flight, never expecting it to sit in a database that eventually gets breached. MAG has temporarily pulled its online "Manage My Booking" tool offline and is routing customers to a phone line instead while it works through the fallout.

Here's how the company put it in its public statement:

"We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems. We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised."

That's a fairly standard breach statement, and it leaves out the part travelers actually care about: what happens to their contact details now that they're loose. Security researchers who cover these incidents routinely flag that batches like this end up feeding phishing and SMS-scam campaigns for months after the headlines fade, because a name, phone number and postcode is more than enough to make a fake "your parking fine is overdue" text look convincing.

Why this matters beyond the UK

Manchester Airport alone handles direct flights to and from India, and between the three MAG airports and the wider Indian diaspora across the UK, a meaningful number of the 8.7 million affected records likely belong to Indian travelers, students and NRI families who've flown through one of these airports in recent years. If you've booked airport parking, a lounge, or Fast Track at Manchester, Stansted or East Midlands and used an Indian phone number or email, it's worth treating this as a "watch your inbox" moment.

It's also a useful contrast for how India handles the same kind of incident. Under India's Digital Personal Data Protection (DPDP) Act, a data fiduciary has to notify India's Computer Emergency Response Team (CERT-In) about a breach within six hours of becoming aware of it — one of the tightest breach-reporting windows anywhere in the world. The UK's regime gives companies up to 72 hours to notify their regulator. Indian airports have been rapidly rolling out their own digital touchpoints too, from DigiYatra's biometric boarding to airport WiFi and lounge apps, all of which quietly collect the same email-and-phone combination MAG just lost. The MAG breach is a preview of what a similar incident would look like on home turf, and a reminder that the convenience layer at airports — WiFi, parking apps, fast-track logins — is often the least protected part of the whole operation.

What to actually do about it

  • Watch for phishing emails or texts referencing car park bookings, Fast Track passes, or "account verification" that claim to be from MAG or its airports.
  • Don't click links in unsolicited messages about parking refunds or booking changes — go directly to the airport's official site or app instead.
  • If you used the same phone number or email for other accounts, consider it slightly more exposed to targeted scam attempts for the next several months.
  • Indian travelers who've used these airports should treat any "urgent" message referencing their trip with the same suspicion as a bank OTP scam call.

None of this breach involved anything as dramatic as flight data or passports, which is probably why it hasn't dominated headlines the way the Collins Aerospace check-in ransomware attack did last year. But that's exactly the pattern worth noticing: the parts of an airport that feel the most trivial — a WiFi login, a parking booking — are turning out to be the easiest doors in.

Short URL: https://code24.in/e586068e

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Code24 Team Code24 Team