MAG, which runs Manchester Airport, London Stansted, and East Midlands Airport, confirmed the incident in a statement on Friday. The company, which recently celebrated a record 66 million passengers in a year, said it acted quickly to contain the breach and engaged external cybersecurity experts to assist with the investigation.
According to a spokesperson, the majority of affected customers—approximately 8.7 million—had only their email addresses compromised. However, some individuals also had their phone numbers, vehicle registrations, or postcodes stolen. The data was collected as part of the airports' car parking reservations, executive lounge bookings, fast-track security services, and public Wi-Fi sign-up processes.
MAG emphasised that at no point was passenger safety or aviation security compromised, and that none of its airports experienced operational disruption. As a precautionary measure, the group temporarily revoked access to its 'Manage My Booking' system. Customers needing to amend or cancel bookings within 72 hours were directed to contact customer services directly.
Affected customers have already been contacted by email. One reader of The Register criticised the handling, noting that receiving the breach notification after being charged £80 for five days of parking at Stansted 'added insult to injury'.
The company apologised for any inconvenience and reiterated that it takes the security of customer information 'extremely seriously'. It advised all customers to remain alert for unsolicited communications that might attempt to exploit the stolen data, though it stressed that visiting the airports remains safe.
The Register asked MAG for additional details on the nature of the attack, including whether ransomware was involved or which specific system was breached. A spokesperson declined to comment beyond the published statement.
Data breaches involving transport hubs are particularly concerning because the stolen information—such as vehicle registrations and email addresses—can be used in targeted phishing campaigns or for credential-stuffing attacks on other services. The Information Commissioner's Office (ICO) is likely to investigate whether MAG complied with data protection regulations under UK GDPR.