ΔΙΕΘΝΗΣ ΕΛΛΗΝΙΚΗ ΗΛΕΚΤΡΟΝΙΚΗ ΕΦΗΜΕΡΙΔΑ ΠΟΙΚΙΛΗΣ ΥΛΗΣ - ΕΔΡΑ: ΑΘΗΝΑ

Ει βούλει καλώς ακούειν, μάθε καλώς λέγειν, μαθών δε καλώς λέγειν, πειρώ καλώς πράττειν, και ούτω καρπώση το καλώς ακούειν. (Επίκτητος)

(Αν θέλεις να σε επαινούν, μάθε πρώτα να λες καλά λόγια, και αφού μάθεις να λες καλά λόγια, να κάνεις καλές πράξεις, και τότε θα ακούς καλά λόγια για εσένα).

Δευτέρα 31 Αυγούστου 2026

Cyberattack exposes data of 8.7m UK airport customers

 

A cyberattack on Manchester Airports Group (MAG) has exposed personal data belonging to around 8.7 million customers across Manchester Airport, London Stansted Airport and East Midlands Airport, while airport operations and  aviation security remained unaffected.

The incident involved an unauthorised third party gaining access to customer information associated with car park, lounge and Fast Track bookings, as well as registrations for Wi-Fi services inside the terminals of the three airports.

The attack took place over the weekend, with MAG becoming aware of the incident on Tuesday, 25 August 2026. The airport operator subsequently restricted access to the affected systems, brought in specialist cyber-security advisers and notified the relevant authorities. The breach was publicly disclosed on Thursday, 27 August.

MAG said hackers demanded a ransom for the data, which the airport group refused to pay. The amount demanded has not been disclosed. The identity of the group responsible has also not been made public.

Approximately 8.7 million customers were affected. However, the majority of the compromised records were limited to email addresses, primarily collected when passengers registered to use Wi-Fi services within airport terminals.

More detailed information was associated with customers who used or enquired about other airport services, including car parking, lounges and Fast Track. Data accessed in the incident included email addresses, telephone numbers, vehicle registration numbers and postcodes.

MAG said neither the group nor the affected system held customers’ bank or payment details. The company also stated that the incident did not involve operational airport systems. “We would like to reassure customers that Manchester Airport Group takes the security of customer information extremely seriously and we apologise for any inconvenience or concern caused.”

The airport operator said passenger safety and aviation security had not been compromised and that the cyberattack had caused no operational disruption. Flights continued to operate normally at Manchester, Stansted and East Midlands airports, while customer parking services also remained operational.

Existing bookings across the three airports remain valid and passengers do not need to take action regarding upcoming reservations. However, MAG temporarily suspended access to its online Manage My Booking service as a precaution following the breach.

Customers needing to amend a booking due within 72 hours were directed to the group’s customer service operation. MAG also said customers wishing to change booking dates or cancel because of the incident could do so without charge, with cancellations linked to the incident eligible for a full refund.

MAG said it contacted affected customers directly after containing the breach. The group is also working with the UK’s National Cyber Security Centre as part of the response to the incident.

“We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems,” MAG said. “We have informed and are working with the relevant authorities.”

The company has advised customers to remain vigilant for suspicious emails, text messages or telephone calls following the theft of the data. It has also warned customers against clicking links or opening attachments contained in unexpected communications.

MAG said it would never unexpectedly contact customers requesting payment card details, banking information or passwords. The combination of email addresses, telephone numbers, postcodes and information linked to airport services could potentially be used in communications presented as originating from an airport or travel-related business.

The cyberattack affected one of the UK’s largest airport operators during the peak summer  travel period. Manchester, London Stansted and East Midlands airports handled more than 66 million passengers during the financial year to March 2026, almost 2% more than in the previous year.

Manchester Airport handled a record 32.3 million passengers during the period, up 3.6%, while Stansted reached 30 million annual passengers for the first time. East Midlands Airport handled approximately four million passengers. Across its three airports, MAG connects passengers with 284 destinations and accounts for around one in five UK air passengers.

The incident follows other cyberattacks affecting  aviation and transport infrastructure. In September 2025, a cyberattack involving Collins Aerospace, a provider of passenger processing systems, disrupted check-in and boarding operations at several European airports, including Heathrow.

In the latest MAG incident, however, operational airport systems were not affected. The group said passengers should continue to travel to Manchester, London Stansted and East Midlands airports as normal while the investigation and response to the data breach continue.

Tags: cyberattack Manchester Airports Group (MAG)