Manchester Airports Group, operator of Manchester, London Stansted, and East Midlands airports, has announced a cyberattack.
According to the group, the affected data includes information from Wi-Fi registrations at the airport as well as bookings for parking spaces, lounges, and the fast-track service. The compromised information includes email addresses, phone numbers, vehicle license plates, and postal codes, although according to the airport group, only the email address was disclosed for the overwhelming majority of those affected.
According to the company, no banking or payment data was stored on the affected system. The group has not yet disclosed how the attackers gained access or who is behind the attack. According to its own statements, the company became aware of the incident on Tuesday, immediately restricted access to the affected systems, brought in specialized cybersecurity experts, and informed the relevant authorities.
After cyberattack: Combination of data facilitates targeted fraud
Muhammad Yahya Patel, virtual CISO and cybersecurity consultant for the EMEA region at Huntress, warned that the combination of contact and travel data provides criminals with a precise target profile for subsequent fraud or phishing campaigns.
“Scammers now know that you traveled, roughly when, and have two direct lines of contact to approach you with a convincing story.”
Muhammad Yahya Patel, Virtual Chief Information Security Officer and Cybersecurity Consultant for the EMEA region at Huntress
Graeme Stewart, Head of Public Sector at security firm Check Point Software, added that the stolen data could now be used in a targeted manner, for example via a fake parking fee refund or an alleged message regarding this exact security incident, making a fraud attempt significantly harder for ordinary customers to recognize.
The affected airport group contacted affected customers directly and warned them about unexpected emails, calls, and text messages. They stated they would never ask unannounced for payment card details, bank information, or passwords. Flight operations, passenger safety, and existing bookings were not affected by the incident, but as a precaution, the company temporarily suspended its online booking management service.
Already several comparable incidents at airports
Airports are generally considered attractive targets for cybercriminals due to the large volume of personal data processed. Back in September 2025, a ransomware attack on Collins Aerospace exposed a 50-gigabyte database and disrupted check-in and boarding at Heathrow, Brussels, Berlin, Dublin, and Cork airports. In February, the ransomware group Qilin also claimed responsibility for an attack on Tulsa Airport, in which attackers allegedly accessed and published airport data, while in early 2026 a suspected cyberattack on Dubai Airport reportedly compromised data, with attackers claiming possession of sensitive recordings, including passport and security scanner footage.
(Editorial Team)