Manchester Airports Group Reports Cyber Incident Affecting Customer Data
Manchester Airports Group (MAG) has confirmed a cyber incident involving unauthorized access to customer data linked to bookings and Wi-Fi registrations across its airports.

Manchester Airports Group (MAG), which operates Manchester, Stansted, and East Midlands airports, has disclosed a significant cyber incident. An unauthorized third party gained access to customer data, impacting information associated with bookings and airport Wi-Fi registrations.
The full scope and the precise methods used by the attackers are still under investigation. MAG has stated that the incident is being thoroughly examined to understand the extent of the breach and to identify any specific vulnerabilities exploited. The group is working with cybersecurity experts to manage the situation and enhance its security measures.
While the investigation is ongoing, MAG has not yet specified the exact nature of the customer data compromised. However, the mention of bookings and Wi-Fi registrations suggests that personal details such as names, contact information, and potentially travel-related data could be involved. The group has not confirmed if financial information was accessed.
MAG has initiated a review of its security protocols and is implementing additional measures to prevent future incidents. The company is also coordinating with relevant authorities and regulatory bodies as the investigation progresses. The focus remains on securing systems and protecting customer information.
This incident highlights the persistent threat of cyberattacks against critical infrastructure and large organizations. Airports, handling vast amounts of sensitive personal and operational data, are attractive targets for malicious actors. The breach underscores the ongoing need for robust cybersecurity defenses and rapid incident response capabilities within the aviation sector.
MAG has not yet provided a timeline for when customers will be notified or what specific steps individuals should take. The company has advised customers to remain vigilant for any suspicious communications that may appear to originate from MAG or its associated services. Further updates are expected as the investigation yields more information.
The Register reports that the cybersecurity incident at Manchester Airports Group (MAG) has led to the theft of customer data including email addresses, phone numbers, vehicle registrations, and postcodes. While MAG stated that passenger safety and aviation security were not compromised and no payment details were stolen, the breach affected data from car parking, lounge, fast track bookings, and public Wi-Fi services. The company is working with authorities and has advised customers to be vigilant against phishing attempts.
The cyberattack on Manchester Airports Group (MAG) has been further detailed, revealing that approximately 8.7 million customers had their data exposed. While the exact timeframe of the breach was not specified, MAG confirmed that in most instances, only email addresses were accessed. The compromised data includes email addresses, phone numbers, vehicle registrations, and postcodes, though the company stressed that no financial or payment card data was exposed. MAG has temporarily suspended its online Manage My Booking service as a precautionary measure.
The cyberattack on Manchester Airports Group (MAG) has been confirmed to have exposed the personal data of approximately 8.7 million customers, including email addresses, postcodes, and vehicle registration details. While payment information was not compromised, the stolen data could be used for sophisticated phishing and social engineering attacks. MAG has refused to pay a ransom demanded by the hackers and has notified authorities, engaging cybersecurity advisors to assist affected customers.
The breach at Manchester Airports Group (MAG) has been confirmed to have affected customer data from three UK airports, with a "quantity" of personal information stolen. While the full scope is still under investigation, the incident underscores the persistent risks to sensitive data held by major travel infrastructure organizations.
The extortion group FulcrumSec has claimed responsibility for the breach, stating they exfiltrated over 80 GB of sensitive data and intend to publish it online. This claim adds a specific threat actor and the scale of data theft to the initial report of the incident.
The threat group FulcrumSec has claimed responsibility for the breach impacting Manchester Airport Group (MAG), alleging the exfiltration of approximately 550GB of data. FulcrumSec claims initial access was gained by exploiting administrative keys for the customer engagement platform Iterable found in the frontend JavaScript of MAG's airport websites. The group has begun leaking the stolen data online, which they state includes extensive personal identifiable information (PII) and booking details.
The hacker group FulcrumSec has claimed responsibility for the breach, stating they gained access by exploiting administrator keys found in the frontend JavaScript of MAG's websites. They have since published approximately 550GB of data, reportedly containing personal information of 8.8 million individuals, including names, emails, phone numbers, and IP addresses, after MAG refused to pay a ransom demand.