Keyboard shortcuts

Aug 27, 2026, 08:24 PM UTC
BREAKINGBusiness // Security

Three UK Airports Breached, With 8.7 Million Customers' Data Accessed

Manchester, Stansted and East Midlands. The hackers took email addresses, phone numbers, vehicle registrations and postcodes.

peatpost Desk
Aggregated
Aug 27, 2026, 02:53 PM UTC3 min read
Three UK Airports Breached, With 8.7 Million Customers' Data Accessed
SourceGuardian Business· 5h ago

Manchester, London Stansted and East Midlands airports have been hit by a cyber-attack in which hackers accessed the data of about 8.7 million customers.

Manchester Airports Group, which operates all three hubs, said the incident involved data relating to "car park, lounge and fast-track bookings and in-airport wifi sign-ups." The attackers obtained email addresses, phone numbers, vehicle registration numbers and postcodes.

The company said that "at no point has passenger safety or aviation security been compromised," that airport operations were unaffected, and that the compromised system did not hold bank or payment details.

The exterior of Manchester airport terminalManchester airport. Most of the accessed data related to wifi sign-ups in the three airports' terminals. Photograph: AP S (uk)/Alamy

The warning to customers

In an email to customers, London Stansted wrote: "We would urge you to be particularly cautious of unexpected emails, calls or text messages claiming to be from us. We will never contact you unexpectedly to ask for payment or banking information. We apologise for any inconvenience or concern this may cause."

That advice points at the real exposure here, and it is worth being precise about why.

Why 'no payment data' is less reassuring than it sounds

The absence of card details limits direct financial fraud. It does not limit the usefulness of what was taken.

An attacker now holds, for millions of people, a verified email address paired with a phone number, a home postcode and — in many cases — a vehicle registration and a record of having booked airport parking. That combination is close to ideal for targeted phishing, because every element can be used to establish credibility.

A message that names your car, your postcode and the airport you actually parked at does not read like a scam. It reads like a service email. Payment details can be cancelled in an afternoon; the fact that you drove a particular car to Stansted cannot.

Vehicle registrations carry a further complication. They are semi-public identifiers that link to insurance records, parking systems and automated number plate recognition databases, and they are frequently used as a verification token by exactly the sort of service that might now be impersonated.

The category of system that failed

The breached data came from car parking, lounge bookings, fast-track passes and terminal wifi sign-ups — the commercial periphery of an airport rather than its operational core.

That distinction explains both the reassurance and the failure. Aviation security systems are heavily regulated, segregated and audited. Wifi captive portals and car park booking engines are ordinary consumer web services, frequently outsourced, and they accumulate personal data at enormous scale precisely because signing up is a condition of using the terminal.

Millions of people handed over an email address to check their messages while waiting for a flight, without any sense that they were joining a database of 8.7 million records. Very few of them would describe that as having become a customer of the airport at all.

What follows

The Information Commissioner's Office will expect notification, and the scale places this among the larger UK consumer breaches of recent years. The regulator's interest is likely to focus on retention: whether wifi sign-up records from years of past visits needed to be held at all, and why a marketing database was reachable from wherever the intrusion began.

For affected travellers the practical steps are narrow but worth taking: treat unexpected contact referencing your travel, parking or vehicle with suspicion, and never act on a payment request arriving by email or text regardless of how much the sender appears to know about you.

Written by
peatpost Desk
Aggregated · @peatpost
Share

Discussion

0 comments
0/2000

No comments yet — be the first to weigh in.

More from peatpost