Key Points
- Personal data of approximately 8.7 million individuals was exposed online after a data breach of Manchester Airports Group (MAG), which is the owner of Manchester, Stansted, and East Midlands airports.
- Among other things, the stolen information consists of emails, phone numbers, home addresses, license plates, shopping history, and browsing devices data. This information was analyzed by HaveIBeenPwned experts.
- On 27 August 2026, MAG reported the cyber-attack that allowed hackers to gain access to data connected to car park, lounge, and Fast Track bookings as well as data about WiFi connections in airport, but there was no information about any credit card or bank details.
- The hacking group FulcrumSec claims responsibility, saying that it managed to steal approximately 86 GB of data exploiting vulnerabilities related to managing digital keys to corporate networks.
- MAG declined the ransom request and has cooperated with cybersecurity advisers and the relevant authorities such as the Information Commissioner’s Office (ICO) since the airport operations and passengers’ safety were not affected during the attack.
- Cybersecurity expert Kevin Beaumont warns the victims to be cautious about potential scams and hacking as the data can be used by criminals trying to target rich people or celebrities.
Manchester (Manchester Mirror) September 02, 2026 – Criminal hackers have posted the personal data of nearly nine million people online after breaching three UK airports last month, in one of the largest cyber security incidents to hit British transport infrastructure. Manchester Airports Group (MAG), which operates the three hubs, confirmed that an unauthorised third party obtained customer data during a cyber security incident at the weekend of 23-24 August 2026, and that the company refused a ransom demand from the attackers.
- Key Points
- Which airports and services were affected by the hack?
- What data was stolen and published by the criminals?
- Who claimed responsibility and how was the breach carried out?
- How is MAG responding and what advice has been given to customers?
- Background of the MAG airports cyber security development
- Prediction: How the MAG data breach can affect passengers and the aviation sector
As reported by the BBC’s technology correspondent, experts in compromised data at HaveIBeenPwned examined the released information and confirmed it includes individuals’ email addresses, phone numbers, residential addresses, vehicle registration numbers, purchase histories and data about their browsing devices. The breach affects approximately 8.7 million customers who used services including airport car parking, lounge access, Fast Track security bookings and in-airport Wi-Fi sign-ups across Manchester, London Stansted and East Midlands airports.
MAG stated that “at no point has passenger safety or aviation security been compromised” during the incident and that airport operations remained unaffected throughout. The company also confirmed that the hacked systems did not hold customers’ bank or payment details, meaning financial information was not exposed in the breach.
Which airports and services were affected by the hack?
The cyber attack targeted Manchester Airports Group, which operates three of the UK’s busiest airports: Manchester Airport in the North West of England, London Stansted Airport in Essex, and East Midlands Airport in Derbyshire. Combined, these three hubs handled 54 million passengers last year, making MAG the UK’s largest airport operator by passenger numbers.
According to a MAG spokesperson, as quoted by The Guardian, the incident involved data related to “car park, lounge and fast-track bookings and in-airport wifi sign-ups” at all three airports. Customers who registered for free Wi-Fi at terminal locations, booked parking spaces in advance, purchased lounge access or bought Fast Track security passes had their information accessed by the hackers.
In an email to customers, London Stansted airport advised:
“We would urge you to be particularly cautious of unexpected emails, calls or text messages claiming to be from us. We will never contact you unexpectedly to ask for payment or banking information.”
The airport operator apologised for any inconvenience or concern caused by the incident.
What data was stolen and published by the criminals?
The compromised data encompasses a wide range of personal information. As confirmed by HaveIBeenPwned, which added the breach to its database on 2 September 2026, the stolen information includes email addresses, phone numbers, names, geographic locations, IP addresses, vehicle registration plates, purchase histories and browser user agent details.
Cybersecurity specialist Kevin Beaumont, who analysed the released data, cautioned those impacted to remain vigilant against various scams and hacking attempts, particularly targeting high-profile or affluent individuals. Beaumont remarked:
“The data encompasses both past locations and intended future travel plans, so those concerned about their movements being exposed should consider taking preventive measures.”
He further noted: “Individuals must be wary of scammers reusing this information, which includes details like phone numbers and vehicle registrations.” The combination of contact details with travel patterns and vehicle information creates significant risks for targeted phishing attacks, identity fraud and potential physical security concerns for those whose movements can be tracked through the data.
Who claimed responsibility and how was the breach carried out?
The hacking group FulcrumSec has publicly claimed responsibility for the MAG data breach. According to reporting by BleepingComputer, FulcrumSec told journalists on 30 August 2026 that it exfiltrated roughly 86 gigabytes of data from MAG’s systems.
As reported by the BBC, the website utilized by the cybercriminals to host the MAG data is accessible on the surface web, unlike most hacker “leak sites” that typically operate on the dark web, which heightens the risk for victims associated with MAG and other firms targeted by the group in recent months.
In addition to releasing the stolen information, the hackers boasted about their methodology, revealing that they exploited vulnerabilities in the way companies manage their digital keys for internal networks, employing the same technique for each breach. Tech Insider reported that FulcrumSec claimed it stole the data via exposed Iterable API keys, suggesting the attackers gained access through misconfigured or compromised application programming interface credentials used for customer communications.
MAG confirmed the attack did not involve ransomware, though the group did demand a ransom for the return of the data, which the company refused to pay. The Information Commissioner’s Office (ICO) has been informed and is assessing the incident.
How is MAG responding and what advice has been given to customers?
In a statement, MAG advised affected customers to stay alert for unsolicited emails, texts and phone calls. The company said: “We want to reassure our customers that Manchester Airport Group prioritizes the security of their information and we sincerely apologise for any distress or inconvenience this incident may have caused.”
A MAG spokesperson told The Guardian:
“We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised. Airport operations remain unaffected and customer parking services continue to operate normally.”
The company confirmed it had “immediately contained the risk” from the incident and was “working with specialist advisers and taking appropriate steps to protect our customers and systems”.
HaveIBeenPwned recommends affected individuals change their passwords on any account where the same credentials were used, enable two-factor authentication wherever supported, and remain vigilant for phishing attempts using the leaked information. Security experts advise customers to watch for suspicious communications claiming to be from MAG or the airports, and to never provide payment or banking information in response to unexpected contact.
Background of the MAG airports cyber security development
Manchester Airports Group has been the subject of previous cyber security scrutiny. The August 2026 breach comes amid growing pressure on suppliers and operators of national infrastructure to improve their cyber-defences following a wave of high-profile attacks against British companies. Last year, incidents ranged from a cyber attack that shut down Jaguar Land Rover operations for weeks to others targeting Marks & Spencer, Harrods and the Co-op food chain.
In 2025, flights were delayed and cancelled at three major European airports, including London Heathrow, after the company behind check-in and boarding software was hit by a cyber attack. Earlier in August 2026, hackers linked to Iran were blamed for a cyber attack that caused the temporary shutdown of a British power plant, though the government said there was no risk to the wider energy system.
Lauren Wills-Dixon, a partner at law firm Gordons, told The Guardian: “Airports sell a number of services including lounge access, parking and fast-track bookings. Wi-fi access also requires customers to input their data. As a result, operators will hold large amounts of customer data and this, together with the increased use of technology, only increases the threat of a cyber-attack.” The MAG incident highlights the vulnerability of critical transport infrastructure to sophisticated cyber criminals seeking to monetise stolen personal data through extortion and dark web sales.
Prediction: How the MAG data breach can affect passengers and the aviation sector
The publication of 8.7 million customers’ data is likely to result in a sustained increase in phishing attacks, identity fraud attempts and targeted scams against affected individuals over the coming months and years. Passengers whose travel patterns, vehicle registrations and contact details are now publicly accessible face heightened risks of personalised social engineering attacks, where criminals use the leaked information to appear more credible when attempting to steal money or additional personal data.
For the aviation sector, the MAG breach may accelerate regulatory pressure on airport operators and airlines to implement stronger data protection measures, particularly around API security and digital key management, following FulcrumSec’s disclosure of their exploitation method. The incident could prompt the Civil Aviation Authority and ICO to issue new guidance on cyber security standards for airports handling large volumes of passenger data.
Affected customers should expect to receive direct communication from MAG with specific advice on protective measures, and may see increased scrutiny from consumer protection groups and parliamentarians questioning whether adequate safeguards were in place for such sensitive travel and location data. The breach’s timing during peak summer travel season, when 54 million passengers annually use MAG airports, amplifies both the immediate impact and the long-term reputational consequences for the operator.
