Cyber-attack hits three airports operated by Manchester Airports Group, resulting in unauthorised access to the personal information of roughly 8.7 million customers. The group that runs the hubs said the incident affected data connected to ancillary services rather than flight operations, and that passenger safety remained unaffected. The disclosure has highlighted vulnerabilities in services linked to travel rather than core security systems.
The material accessed by the attackers related to car park, lounge and fast-track bookings as well as in‑airport wifi sign-ups. Compromised elements included email addresses, telephone numbers, vehicle registration numbers and postal codes. Because the data pertains to services often supplied or managed by third parties, the scale of the leak spans multiple customer touchpoints beyond ticketing and travel records.
The affected airports — Manchester, London Stansted and East Midlands — are among the busiest in the country and serve a broad mix of business and leisure travellers. The operator’s statement that passenger safety is not compromised aims to reassure travellers, while the nature of the exposed information raises concerns about potential misuse such as targeted scams or identity-related fraud. Incidents of this type typically prompt internal security reviews and increase scrutiny on how personal data is handled across the aviation supply chain.
Customers whose information may have been accessed are likely to face increased risk of unsolicited contact and should exercise caution with unexpected messages. For further information, passengers can consult Manchester Airports Group and advisories from their service providers. The event underscores the importance of robust cybersecurity and data protection measures across air travel services, and is expected to prompt reviews by operators and their partners to reduce exposure to similar breaches in future.


