Airport group says no payment details were accessed and operations remain unaffected, as it works with authorities to investigate the breach.

Manchester Airports Group (MAG) has confirmed that it has been the target of a cybersecurity incident carried out by an unauthorised third party, resulting in the exposure of a quantity of customer data. The group operates Manchester, London Stansted and East Midlands airports, and said the breach relates to information gathered through car park, lounge and Fast Track bookings, as well as in-airport WiFi sign-ups.
MAG said it acted swiftly once the incident was identified, moving to limit its impact and protect both customers and internal systems. The organisation has engaged specialist cybersecurity advisors to support its response and has notified the relevant authorities, who it continues to work alongside as investigations progress.
No impact on operations or passenger safety
The group has stressed that passenger safety and aviation security have not been compromised at any point during the incident, and that airport operations across all three sites remain unaffected. Car parking services continue to operate as normal, and there has been no disruption to flights or terminal operations as a result of the breach.
According to MAG, the data accessed does not include any banking or payment information, as neither the company nor the affected system store such details. However, the unauthorised party did obtain customer email addresses, phone numbers, vehicle registrations and postcodes tied to bookings and WiFi sign-ups across the three airports.
“At no point has passenger safety or aviation security been compromised.”
As a precautionary measure, MAG has temporarily suspended access to its online Manage My Booking service while the investigation continues. Customers with bookings due within the next 72 hours who need to make urgent changes have been directed to contact the group’s customer services team by phone, though MAG has warned that call waiting times may be longer than usual.
Customers wishing to make urgent amendments have been given a dedicated number to call, with MAG confirming that its customer services team is operating extended availability to handle enquiries linked to the incident. The group has asked for patience given the volume of calls, while stressing that no action is required from customers whose bookings fall outside the 72-hour period.
The group has confirmed that all existing bookings remain valid and unaffected by the incident, meaning customers do not need to take any action regarding reservations that fall outside the 72-hour window. MAG said it has contacted customers believed to have been affected directly, and is advising them to remain alert to unexpected communications.
Guidance issued alongside the statement urges customers to be wary of suspicious emails, text messages or phone calls, and to avoid clicking on links or opening attachments from unfamiliar sources. MAG reiterated that it would never contact customers unexpectedly to request payment card details, banking information or passwords, and pointed affected individuals towards the National Cyber Security Centre’s guidance on data breaches for further support.
The incident adds to a growing list of cybersecurity challenges facing the aviation sector, with airport groups increasingly required to defend both operational technology and customer-facing systems against unauthorised access. MAG’s Data Protection team is overseeing its response, working to ensure that all actions taken remain thorough and in line with the group’s legal obligations.
The group also confirmed that the incident does not involve operational airport systems and has no bearing on activity at London Stansted or its other sites, meaning passengers can continue to travel as normal. A MAG spokesperson said the company was continuing to take appropriate steps to safeguard customers and systems while the response continues.
“We would like to reassure customers that Manchester Airport Group takes the security of customer information extremely seriously and we apologise for any inconvenience or concern caused,” the spokesperson added.
Lauren Wills-Dixon, partner and head of privacy at law firm Gordons, said:
“The news that Manchester, Stansted and East Midlands airports have been the subject of a cyber attack will be concerning for customers. So far we know that around 8.7 million customers have had their data stolen, including email addresses, phone numbers and postcodes, but not bank details. The scale of this attack is notable - the important thing now is how Manchester Airports Group (MAG), which operates all three airports, responds in line with its cyber security plan.
“This is another reminder of the importance for organisations to take legal, regulatory and best practice measures to build and maintain cyber resilience. Airports sell a number of services including lounge access, parking and fast-track bookings and there are complex data processing and sharing arrangements in place with airlines and other third parties. Wi-fi access also requires customers to input their data. As a result, operators will hold large amounts of customer data and this, together with the increased use of technology, only increases the threat of a cyber attack.
“MAG has done the right thing in communicating early with affected customers, and has already said it’s working with specialist advisors who will be taking appropriate action to contain the risk and inform the Information Commissioner’s Office in line with guidance.”




No comments yet