The breach, disclosed on August 27, 2026, targeted the digital infrastructure of MAG, one of the UK’s largest airport operators. According to the company, the incident did not affect core aviation systems, air traffic control, or security protocols, and no evidence suggests that passport or payment data was compromised.
MAG stated that the attack involved unauthorized access to customer data associated with ancillary services. The compromised information includes email addresses, phone numbers, vehicle registration numbers, and postcodes—data typically collected for parking reservations, lounge bookings, fast-track passes, and WiFi connectivity. The scale of the breach, affecting 8.7 million customers, raises significant privacy and security concerns for travelers who have used these services at the three hubs.
In a statement, MAG emphasized that it is working with the National Cyber Security Centre (NCSC) and other relevant authorities to investigate the incident and mitigate further risks. The company has begun notifying affected individuals and advised them to remain vigilant against potential phishing attacks or identity fraud, as the stolen data could be used for social engineering scams.
The attack adds to a growing list of high-profile cyber incidents targeting critical infrastructure and transportation hubs worldwide. While MAG has not disclosed the identity or motive of the attackers, cybersecurity experts note that the targeting of airport ancillary services is a common tactic to harvest large datasets for extortion or credential-stuffing attacks.
Industry observers warn that the breach could erode consumer trust in airport digital services, particularly those requiring personal information. The affected airports are major gateways for domestic and international travel: Manchester serves as a key hub for northern England, Stansted is a major London airport for budget carriers, and East Midlands supports freight and passenger operations in central England.