Manchester Airports Group Confirms Data Theft From Wi-Fi Sign-ups and Booking Systems
Hackers pulled email addresses, phone numbers and car registrations from MAG's systems. Payment details were not touched, and flights are running normally.

Key points
- Manchester Airports Group (MAG), which runs Manchester, London Stansted and East Midlands airports, said hackers broke into its systems and stole customer data.
- Stolen data includes airport Wi-Fi sign-ups plus car park, lounge and Fast Track booking details: emails, phone numbers, vehicle registrations and postcodes.
- Payment card data was not accessed and flight operations are unaffected, the company said.
- MAG has temporarily switched off its online "Manage My Booking" page and is pushing customers to the phone line.
- Local UK media put the number of affected travellers as high as 8.9 million, a figure MAG has not publicly confirmed.
MAG, the UK's biggest airport operator, told customers on Tuesday that intruders got into its systems and made off with personal data tied to Wi-Fi logins and pre-travel bookings across its three airports. The group handles more than 66 million passengers a year.
The stolen records cover people who signed up for free airport Wi-Fi, and anyone who booked car parking, an airport lounge, or a Fast Track security pass. MAG said the criminals took email addresses, phone numbers, postcodes and, for parking customers, vehicle registration numbers.
Payment card details were not in the pile, according to the company. Airport operations, including check-in and car parks, are running normally.
What actually got stolen?
Contact and travel-admin data, not financial data. Think of the details you type into a website to book a parking bay or connect a laptop to airport Wi-Fi: name, email, mobile number, postcode, and (for drivers) the car's number plate.
MAG has not said how the hackers got in, how long they were inside, or how many people are affected. UK outlets have reported a figure of up to 8.9 million travellers, citing private company briefings. BleepingComputer, which first reported the incident, said it could not verify that number. Threat Vectr has not confirmed it either.
No ransomware crew or extortion group, criminals who publish stolen data to force a payout, has publicly claimed the attack.
Should travellers be worried?
Be alert, but don't panic. The stolen data is exactly the raw material scammers use for convincing phishing messages, fake emails or texts that pretend to be from a company you trust.
Expect a rise in emails and text messages that name-drop your recent parking booking, your car's registration, or the airport you flew from. Do not click links inside them. Go to the airport's website directly if you need to check something.
MAG said it will never ask customers for card details, bank details or passwords by email or phone. Anyone getting a message that does ask should refuse and report it. The UK's National Cyber Security Centre publishes step-by-step advice for people caught up in a breach, and MAG is pointing customers to it.
What has MAG done so far?
The company said it locked down the affected systems as soon as it spotted the intrusion, brought in outside investigators, and told law enforcement. It has also emailed the people it believes were caught up in the theft.
The online "Manage My Booking" tool is offline for now. Customers who need to change a parking or lounge reservation are being asked to call in instead.
| Detail | What MAG has said |
|---|---|
| Airports affected | Manchester, London Stansted, East Midlands |
| Data stolen | Emails, phone numbers, postcodes, vehicle registrations |
| Payment data | Not accessed |
| Operational impact | None; flights and parking running normally |
| Online booking management | Temporarily suspended |
| Reported scale (unconfirmed) | Up to 8.9 million travellers |
MAG employs 40,000 staff and reports annual revenue of £1.5 billion, so the affected customer base is large by any measure. Expect more detail once the outside investigators finish their work.



