Manchester Airports Group says the overwhelming majority of people affected by a major data breach had an email address exposed, while a smaller number had additional contact and booking information compromised.
MAG has disclosed a breach affecting around 8.7 million customers across Manchester, London Stansted and East Midlands airports. It confirmed the incident on 27 August after an unauthorised third party obtained customer information connected to airport Wi-Fi registrations and bookings for car parking, lounges and Fast Track.
The exposed information could include email addresses, phone numbers, postcodes and vehicle registrations. Bank and payment-card details were not held in the affected system, and MAG said the incident did not affect airport operations, passenger safety or aviation security.
For most customers the exposure was limited to an email address. Many were collected when travellers registered to use public Wi-Fi. A smaller proportion had further information exposed through enquiries or completed bookings.
MAG said attackers compromised one of its own systems and then took files from a database hosted by a third party. It has not identified the system. The company describes the incident as a sophisticated attack rather than a lapse such as staff giving away credentials.
The Information Commissioner’s Office asked MAG not to publish the ransom note, the extortion demands or the name of the group behind them. MAG said the demands were lower than the group is known to ask for, on the ICO’s understanding, and that it has not paid.
The breach was claimed by data-extortion group FulcrumSec, which told BleepingComputer it had obtained around 86GB of data. BleepingComputer reviewed samples and validated one traveller’s information against genuine Fast Track purchases. The material reportedly included booking references, purchase history, travel timings, spending information, IP addresses and customer-engagement data. It could not verify the total volume claimed or the group’s account of how access was obtained.
FulcrumSec says it used airport-specific Iterable API credentials exposed in client-side JavaScript, and that the haul includes close to 200,000 records tied to travel still to come in 2026. MAG has not confirmed either claim, and there is no evidence that a vulnerability in Iterable itself was responsible. Marketing platforms holding customer data have drawn scrutiny before, including Klaviyo signup forms reported to have shared passwords with advertisers.
Millions of exposed email addresses create a phishing risk even without financial data or passwords. An address tied to a known airport relationship gives an attacker context for impersonation. Where booking details were also taken, fraudulent messages can cite genuine services and travel dates, and the records for future trips carry their own timing. A recent Spanish case showed how far real transaction details plus a lookalike domain can carry an attack.
MAG has advised customers to watch for suspicious emails, texts and calls, and said it will not unexpectedly request passwords, banking information or payment details. It has restricted access to affected systems, engaged cyber security specialists and notified the relevant authorities.
The full extent of the data taken and the method used remain under investigation.









