← All stories
● Covered by 5 sources · 7 reportsMedium impact7 negative

Cyberattack Exposes Data of 8.7 Million Customers at Three UK Airports

🔄 Updated 28d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • 8.7 million customer data records exposed.
  • Affected airports: Manchester, London Stansted, East Midlands.
  • Compromised data includes email, phone, vehicle registration, postcode.
  • No financial data or passenger safety compromised.
  • Incident occurred during peak summer travel season.
  • Compromised data includes Wi-Fi sign-ups, car park, lounge, and Fast Track bookings.
  • MAG temporarily suspended its online “Manage My Booking” service.
  • MAG is the UK’s largest airport operator.
  • MAG airports handle over 66 million passengers yearly.
  • MAG employs 40,000 people.
  • MAG generates annual revenue of £1.5 billion.
  • FulcrumSec claimed responsibility for the data breach.
  • FulcrumSec stole approximately 86 GB of data.
  • The breach exposed more detailed customer, booking, and travel information.
  • The breach potentially impacts nearly 200,000 upcoming travel records.
  • BleepingComputer validated one record against a traveler's purchase history.
  • MAG refused to pay a ransom.
  • Compromised data includes purchasing history and browsing device data.
  • The cyber-crime group is offering the entire data set for free.
  • The data set is 0.5 terabytes.
  • 8.8 million people's data was leaked.
  • The stolen information was stored in a third-party database.
  • The data includes residential IP addresses.
  • The data includes names and town/postal region.

Data Breach at UK Airports

Manchester Airports Group (MAG), which operates Manchester, London Stansted, and East Midlands airports, announced a cyberattack that exposed customer data. The incident affected approximately 8.7 million individuals who used services at these three airports.

The compromised information includes email addresses, phone numbers, vehicle registrations, and postcodes. This data was associated with car park, lounge, and Fast Track bookings, as well as in-airport Wi-Fi sign-ups.

No Financial Data or Safety Compromised

MAG stated that the affected system did not store customers' bank or payment card details, and no financial data was exposed. The company also confirmed that passenger safety and aviation security were not compromised, and airport operations remained unaffected.

London Stansted advised customers to be cautious of unexpected emails, calls, or text messages claiming to be from the airport, emphasizing that they would not request payment or banking information unexpectedly.

Context of the Attack

The cyberattack occurred during the peak summer travel season, a period when many families were returning to the UK before the start of the new school year. The three airports collectively handled over 65 million passengers in the previous year, though not all would have interacted with the affected services.

MAG did not disclose how the attackers gained access to their systems or the full extent of their activities beyond accessing customer data.

Updates

🕒 2026-09-03 · new reporting from SecurityWeek
  • 8.8 million people's data was leaked.
  • The stolen information was stored in a third-party database.
  • The data includes residential IP addresses.
  • The data includes names and town/postal region.
🕒 2026-09-02 · new reporting from BBC Technology
  • MAG refused to pay a ransom.
  • Compromised data includes purchasing history and browsing device data.
  • The cyber-crime group is offering the entire data set for free.
  • The data set is 0.5 terabytes.
🕒 2026-08-30 · new reporting from BleepingComputer
  • FulcrumSec claimed responsibility for the data breach.
  • FulcrumSec stole approximately 86 GB of data.
  • The breach exposed more detailed customer, booking, and travel information.
  • The breach potentially impacts nearly 200,000 upcoming travel records.
  • BleepingComputer validated one record against a traveler's purchase history.
🕒 2026-08-27 · new reporting from BleepingComputer
  • Compromised data includes Wi-Fi sign-ups, car park, lounge, and Fast Track bookings.
  • MAG temporarily suspended its online “Manage My Booking” service.
  • MAG is the UK’s largest airport operator.
  • MAG airports handle over 66 million passengers yearly.
  • MAG employs 40,000 people.
  • MAG generates annual revenue of £1.5 billion.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Data from the Manchester Airports Group (MAG), including personal information for 8.8 million individuals, was leaked online by the FulcrumSec extortion gang after MAG refused to pay a ransom. The breach exposed email addresses, phone numbers, and other booking-related data from Manchester, London Stansted, and East Midlands airports, impacting a significant number of travelers.

Criminal hackers have published the personal data of nearly 9 million customers from Manchester, London Stansted, and East Midlands airports after Manchester Airports Group (MAG) refused to pay a ransom. The exposed data includes contact details, vehicle registrations, postcodes, purchasing history, and browsing device data, increasing the risk of secondary attacks and scams for affected individuals.

The FulcrumSec extortion group has claimed responsibility for a data breach at Manchester Airports Group (MAG), which operates Manchester, London Stansted, and East Midlands airports. The group claims to have stolen 86 gigabytes of data, including booking and travel information, and plans to leak it, impacting potentially millions of customers.

The extortion group FulcrumSec claimed responsibility for a data breach at Manchester Airports Group (MAG), stating they stole approximately 86 GB of data. This incident is significant as the stolen data appears to include more detailed customer, booking, and travel information than MAG initially disclosed, potentially impacting nearly 200,000 upcoming travel records.

Manchester Airports Group (MAG) announced a data breach where hackers stole customer data, including Wi-Fi sign-ups and booking details, from Manchester, Stansted, and East Midlands airports. This incident is significant because it impacts personal information for potentially millions of travelers, although payment details and airport operations were unaffected.

Manchester, London Stansted, and East Midlands airports experienced a cyber-attack, compromising data for approximately 8.7 million customers. The breach involved personal information from car park, lounge, fast-track bookings, and in-airport Wi-Fi sign-ups, highlighting the ongoing cybersecurity challenges for critical infrastructure operators.

Manchester Airports Group (MAG) announced a cyberattack exposed customer data for approximately 8.7 million individuals across its three airports. The compromised information includes email addresses, phone numbers, vehicle registrations, and postcodes, but no financial data was accessed.