Manchester Airports Group (MAG), the operator of Manchester, Stansted, and East Midlands airports, has confirmed that an unauthorized party stole customer data tied to all three hubs. The company said the intruders obtained a batch of information from car park, lounge, and Fast Track bookings, along with sign-ups for in-airport WiFi.
The exposed records include email addresses, phone numbers, vehicle registrations, and postcodes. MAG stressed that neither it nor the compromised system holds bank or payment details, and that the incident was not a ransomware attack. The Register reports the scale is currently thought to be around 8.7 million customers, with email addresses from public WiFi sign-ups making up the overwhelming majority.
The company said it contained the risk, is working with specialist advisors, and has informed the relevant authorities. “At no point has passenger safety or aviation security been compromised,” MAG said in a statement. It has not paid the extortionists, and described the intrusion as a sophisticated hack rather than a human mistake, with files taken from a database hosted by a third party.
The online Manage My Booking portal has been switched off as a precaution, and passengers needing to change or cancel bookings within 72 hours must call customer service. Airport operations continue normally, and the Information Commissioner’s Office has asked MAG not to disclose the ransom note, the demands, or the group’s name.
