Data breach
Manchester Airports Group
- Records
- 273,558,352
- Breach date
- 1 September 2026Estimated
- Added
- 12 September 2026
What was exposed
5 types of data · 6 more reported · 1 puts you at serious risk
- Email addresses273,558,352
- Names1,326,080
- Phone numbers1,293,237
- Dates of birth5,575
- Passport numbers5,005
- Licence platesReported, not counted
- PostcodesReported, not counted
- CitiesReported, not counted
- IP addressesReported, not counted
- Purchase historyReported, not counted
- VehiclesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
The Manchester Airports Group (MAG), the UK's largest airport operator, is at the center of a data breach in which an extortion group leaked roughly 550 gigabytes of customer data after the company reportedly refused to pay a ransom. MAG disclosed the incident on August 27, 2026, confirming that an unauthorized third party accessed customer data tied to car park, lounge, and Fast Track bookings, as well as in-airport Wi-Fi registrations at Manchester, London Stansted, and East Midlands airports. According to SecurityWeek, data published online includes the email addresses and phone numbers of approximately 8.8 million people. The investigation team has indexed more than 273 million records associated with this listing. The group claiming the breach, FulcrumSec, says it gained access using API keys for the marketing platform Iterable that were embedded in the publicly readable JavaScript of MAG's three airport websites, though the group's claims have not been independently verified.
August 25, 2026: MAG detected unauthorized access to its systems, according to the company's disclosure.
August 27, 2026: MAG publicly disclosed the breach and reported it to law enforcement, the National Cyber Security Centre, and the Information Commissioner's Office.
August 30, 2026: FulcrumSec claimed responsibility, telling BleepingComputer it had stolen approximately 86 gigabytes of data and planned to publish it.
September 2, 2026: Infosecurity Magazine reported that FulcrumSec had posted roughly 549 gigabytes of claimed customer data on its leak site, after MAG declined to pay.
What Information Was Compromised?
Our analysis found the following data types in this breach: 273,558,352 email addresses, 1,293,237 phone numbers, 1,326,080 names, 5,575 birth dates, and 5,005 passport numbers.
MAG's own notice confirmed that email addresses, phone numbers, vehicle registrations, and postcodes were taken from car park, lounge, and Fast Track booking records and Wi-Fi sign-ups. The company said no payment card or banking information was stored in the affected systems.
FulcrumSec's claims, reported by SecurityWeek and Infosecurity Magazine, go further: nearly 8.7 million customer profiles including names, mobile numbers, home towns, and residential IP addresses; around 2.5 million purchase records; over 461,000 SMS messages containing booking dates and vehicle registrations in plain text; roughly 108,000 unique vehicle registration plates; and data on nearly 191,000 future bookings, including travel dates, terminal information, and vehicle details.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Most affected customers had only an email address exposed, which limits direct harm but still opens the door to phishing emails that impersonate MAG or travel brands. For customers who used parking, lounge, or Fast Track services, the exposure is broader. Phone numbers combined with real booking details make convincing scam calls and text messages possible. Vehicle registration plates paired with postcodes and future travel dates raise a more physical concern: burglars could use upcoming trip dates to target empty homes, as Infosecurity Magazine noted. The leaked residential IP addresses and device details add to the risk of targeted scams.
What Is Manchester Airports Group Doing in Response?
MAG says it refused the ransom demand and reported the incident to law enforcement, the National Cyber Security Centre, and the Information Commissioner's Office within the UK GDPR's 72-hour notification window. The company temporarily suspended access to its online "Manage My Booking" service. MAG has stated that airport operations, passenger safety, and aviation security were unaffected, and that no payment information was accessed. As of September 25, 2026, no updated public notice from MAG addressing the published leak had been reported in sources reviewed.
What Should You Do If You Were Affected?
Treat any message that references your bookings, travel dates, parking confirmations, or vehicle registration as suspicious, even if it contains accurate details.
Do not click links or open attachments in unexpected emails or texts about airport bookings.
Be alert for phishing emails, since most affected people had at least an email address exposed.
If you used car parking, lounges, or Fast Track, watch for scam calls and texts referencing your vehicle or travel plans.
Report suspected fraud to Action Fraud at actionfraud.police.uk or by calling 0300 123 2040.
In the news
- SecurityWeek: Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusalsecurityweek.com (opens in a new tab)
- SecurityWeek: Extortion Group Claims Manchester Airports Group Data Breachsecurityweek.com (opens in a new tab)
- Infosecurity Magazine: FulcrumSec Claims Responsibility for Manchester Airport Group Breachinfosecurity-magazine.com (opens in a new tab)
- TechTimes: Manchester Airports Group Breach: FulcrumSec Stole 86 GB Without Hackingtechtimes.com (opens in a new tab)
