Manchester Airports Group (MAG) has confirmed a cyber security incident in which an unauthorized third party accessed data associated with 8.7 million customers.
The airport operator, which owns Manchester, London Stansted and East Midlands airports, stated on August 27:
“A quantity of customer data has been obtained that relates to car park, lounge and Fast Track bookings and in-airport WIFI sign-ups at Manchester, Stansted and East Midlands airports,”
The cyberattack occurred over the weekend, a MAG spokesperson told CX Today. Given the nature of the ongoing investigation, the company was unable to provide further details about breach, the spokesperson added.
“We have informed the National Cyber Security Centre and reported the incident to the Information Commissioner’s Office.”
The company said the compromised information includes customers’ email addresses, phone numbers, vehicle registration numbers and postcodes. It stressed that “neither MAG nor the system accessed by the attacker holds customers’ bank or payment details.”
MAG said it immediately contained the affected system. “At no point has passenger safety or aviation security been compromised.”
“The incident has not resulted in any operational disruption. Airport operations remain unaffected and customer parking services continue to operate normally,” the statement added.
MAG Warns Customers Over Phishing and Impersonation Risks
The company has issued a warning to affected customers to be particularly cautious of unexpected emails, calls or text messages claiming to come from MAG.
“We would urge you to be particularly cautious of unexpected emails, calls or text messages claiming to be from us. We will never contact you unexpectedly to ask for payment or banking information.”
The warning is particularly relevant given the nature and scale of the data exposed. While the information does not include payment details, a combination of email addresses, phone numbers, postcodes and vehicle registrations could provide useful material for targeted phishing and impersonation attempts.
A scammer who knows that an individual has used airport parking or another MAG service could potentially use that information to make a fraudulent message appear more credible.
Why Travel Industry Customer Data Is Increasingly Valuable
The incident highlights the growing security challenge around the digital services that have become part of the airport customer journey.
Airport operators collect customer information through a wide range of services beyond ticketing and passenger processing. Parking bookings, airport lounges, Fast Track services and Wi-Fi registration all require varying amounts of personal information.
That creates a large customer-data footprint around an organization whose core infrastructure is also considered critical national infrastructure.
Although the company has confirmed that aviation security and passenger operations were unaffected, a compromise of customer-facing systems can still create significant consequences for customers.
That the data relates to 8.7 million customers makes the incident one of the more substantial U.K. security breaches disclosed in 2026.
The Customer Experience Fallout
The incident at MAG raises a broader question about how organizations protect the data collected by the digital services customers increasingly depend on.
Parking reservations, lounge access, Fast Track bookings and Wi-Fi registration are designed to remove friction from the airport experience, but they require organizations to collect and process customer information across multiple systems.
A security incident affecting those services can extend far beyond the immediate technical breach.
Customers may subsequently face convincing phishing attempts, uncertainty about whether communications from the airport are genuine, or concerns about using digital airport services in the future.
The response consequently becomes part of the customer experience.
For the airport operator, the next questions will center on how the affected system was compromised, whether the vulnerability has been fully remediated and whether other customer-facing systems have been reviewed.
The MAG incident also comes at a time when the value of travel industry data is receiving increased attention from technology companies and AI developers.
Google’s recent $10MN bid for data from bankrupt U.S. carrier Spirit Airlines has highlighted the growing commercial value of information generated through everyday travel operations. The initial dataset being sold includes extensive operational records, employee information, communications and workflow data, and Spirit intends to conduct a separate sale process for its customer list.
The case raises questions about how travel companies should govern data that is generated through customer interactions and day-to-day operations, particularly when information can potentially be reused for AI development. It also indicates why the security of customer and operational data has become a more significant business concern, as information held by travel companies can have value well beyond its original purpose.
This creates a dual challenge for travel companies. Customer data needs to be protected because it can cause harm when compromised, while the growing commercial value of enterprise and customer information makes it increasingly important to establish where data can be stored, accessed, shared and ultimately reused.
The MAG incident indicates the importance of understanding exactly what customer data travel organizations hold, where it is stored and who can access it.