Manchester Airports Group breach exposes 8.7 million customers
Manchester Airports Group disclosed a data security incident in which an unauthorized third party obtained personal details relating to around 8.7 million customers of car-park, lounge and in-airport Wi-Fi services across its Manchester, Stansted and East Midlands airports.
- Victim
- Manchester Airports Group (MAG)
- records
- 8.7M
On 27 August 2026, Manchester Airports Group (MAG) β the UK operator of Manchester, London Stansted and East Midlands airports β disclosed that an unauthorized third party had obtained customer data held by systems supporting its car-park, lounge, Fast Track and in-airport Wi-Fi services. Reporting citing the company placed the affected population at around 8.7 million customers.
The compromised information could include email addresses, telephone numbers, postal codes and vehicle registration numbers used for those ancillary services. MAG emphasized that neither it nor the accessed systems held customers' bank or payment card details, and that at no point had passenger safety or aviation security been affected. The company said it had moved quickly to contain the risk and was working with specialist advisers and the relevant authorities.
What happened
The incident was subsequently claimed by a group calling itself FulcrumSec, which published email addresses and phone numbers it linked to the breach. According to security analysis, the attackers said they had simply extracted an API key exposed in the website's JavaScript β an access-control failure rather than a sophisticated intrusion β and used it to pull customer records at scale.
Why it matters
The MAG breach shows how much sensitive personal data now sits in the peripheral digital services around an airport β parking, lounges, Wi-Fi β rather than in core operational systems. It is also a stark reminder that hardcoded secrets exposed in client-side code remain one of the most common and preventable causes of large-scale data exposure, allowing millions of records to be scraped without breaching the core network.
Timeline
Manchester Airports Group discloses a data security incident affecting around 8.7 million customers.
The FulcrumSec group claims responsibility and begins publishing email addresses and phone numbers.
Sources
- manchesterairport.co.ukhttps://www.manchesterairport.co.uk/help/data-security-incident/
- helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/08/28/manchester-airports-group-data-breach/
- bitdefender.comhttps://www.bitdefender.com/en-us/blog/hotforsecurity/manchester-airports-group-data-breach-8-7-million
- haveibeenpwned.comhttps://haveibeenpwned.com/Breach/ManchesterAirportsGroup