AvioRadar

Follow us on Social Media

AvioRadar is a part of Nordstorm Aviation

AvioRadar © 2026

Follow us on Social Media

AvioRadar is a part of Nordstorm Aviation

AvioRadar © 2026

Cyberattack on three UK airports: Data of 8.7 million customers stolen, hackers demand ransom

Reading time: 4 minutes

© London Stansted Airport

Hackers gained unauthorised access to data linked to approximately 8.7 million customers of Manchester Airports Group (MAG), which operates Manchester, London Stansted and East Midlands airports, during the weekend of August 22 and 23, 2026. MAG discovered the attack on Tuesday, August 25, and publicly disclosed the incident on August 27.

Following the theft, the attackers demanded a ransom, but the UK’s largest airport group refused to pay. The amount demanded has not been disclosed. MAG confirmed to British media that it knows the identity of the group responsible for the attack and has passed the information to the relevant authorities, although the attackers have not been publicly named. The BBC reported that a ransom was demanded in exchange for the stolen data, while MAG confirmed to ITV News that it had refused to pay.

According to information MAG provided to technology publication The Register, this was not a conventional ransomware attack in which computer systems are encrypted and rendered unusable. Instead, the attackers gained unauthorised access to a customer database, extracted information and then attempted to use it for extortion.

The attack compromised data collected through free terminal Wi-Fi services and bookings for airport parking, lounges and Fast Track services. Most of the affected records contained only the email addresses of customers who had registered to use the airports’ Wi-Fi networks. Some records linked to bookings also included telephone numbers, postcodes and vehicle registration numbers.

MAG stressed that the compromised system did not contain bank account or payment card details. According to the group’s official statement, operational airport systems were not affected, meaning passenger safety, security screening, aircraft handling and airport operations were never compromised.

Flights and parking services continued without interruption, although MAG temporarily suspended its online Manage My Booking service as a precaution. All existing bookings remained valid, while passengers were offered free changes or cancellations for bookings affected by the incident.

After discovering the attack on August 25, MAG restricted access to the affected systems, brought in external cybersecurity specialists and notified customers identified as having been affected by email. The UK’s National Cyber Security Centre (NCSC) and Information Commissioner’s Office (ICO) were also informed.

The scale of the incident is particularly significant given the size of MAG’s operations. Manchester, London Stansted and East Midlands airports handled a record 66.3 million passengers in the financial year ending March 31, 2026, according to the group’s latest annual results.

Although the stolen information does not provide direct access to bank accounts, it could be used to create significantly more convincing fraud attempts. A message containing a correct email address, telephone number, postcode or vehicle registration number may appear to have genuinely come from the airport, particularly if it refers to an alleged parking booking, refund or unpaid charge.

MAG has therefore urged customers to remain vigilant when receiving unexpected emails, calls or text messages and to avoid opening attachments or links from unknown senders. The group stressed that it would never unexpectedly request payment card details, banking information or passwords. Similar advice has been issued by the UK’s National Cyber Security Centre, which warns that information obtained through large data breaches is frequently used in targeted phishing attacks.

Unlike the September 2025 cyberattack against Collins Aerospace, which affected check-in and boarding systems and led to flight cancellations at several European airports, the latest incident remained limited to customer data and related digital services. Nevertheless, it demonstrates that a cyberattack does not have to target air traffic control or operational systems directly to have potentially serious consequences for the aviation sector.

MAG has not yet disclosed how the attackers gained access to the system, how many customers had only their email addresses exposed and how many had additional information compromised, or whether the stolen data has already been published or offered for sale. The investigation into the incident therefore remains ongoing.