Cyber attack on Manchester Airports Group exposes data of 8.7 million customers
Hackers accessed personal data of 8.7 million customers of Manchester Airports Group, which operates Manchester, Stansted and East Midlands airports. Email addresses, phone numbers, vehicle registrations and postcodes were among the information stolen.
Hackers have accessed personal data belonging to approximately 8.7 million customers of Manchester Airports Group, the company that operates Manchester, London Stansted and East Midlands airports. The breach exposed email addresses, phone numbers, vehicle registrations and postcodes, raising concerns about the scale of personal information now in the hands of cybercriminals.
The attack targeted the group's customer database, which holds records for passengers and visitors who used services across the three airports. While the company has not confirmed the exact method used by the attackers, the incident adds to a growing list of cyber attacks against critical infrastructure operators in the United Kingdom. The affected airports serve millions of travellers annually, with Manchester being one of the busiest hubs outside the London area.
Manchester Airports Group has informed the relevant authorities and is working to notify affected customers. The company has advised those impacted to remain vigilant against phishing attempts and unsolicited communications, as stolen email addresses and phone numbers are commonly used in follow-on scams. Vehicle registration data, which was also compromised, could potentially be used in fraudulent parking claims or other identity-related offences.
The breach is among the largest reported by a UK airport operator in recent years. It highlights the vulnerability of travel infrastructure to cyber threats, particularly as airports increasingly rely on digital systems for booking, parking and passenger management. Industry analysts note that the travel sector has become a frequent target for hackers because of the volume of personal and financial data it processes daily.
Authorities have not disclosed whether a specific group has claimed responsibility for the attack. Investigations are ongoing, and the company has said it is cooperating with law enforcement and data protection regulators. Under UK data protection law, Manchester Airports Group could face significant fines if found to have failed in its duty to safeguard customer information.
Affected customers have been urged to monitor their accounts for unusual activity and to change passwords, particularly if they reused the same credentials across multiple online services. The company has also warned against responding to emails or messages that request additional personal information, as these could be part of a wider fraud campaign linked to the stolen data.
The incident serves as a reminder of the persistent threat posed by cyber attacks to essential services. As airports and other transport operators expand their digital footprints, the need for robust security measures and rapid incident response has never been more critical. The full impact of this breach, including any potential misuse of the stolen data, may not be known for some time.
