Contact us 0113 8000 192 / 0330 1700 092

Manchester Airport Data Breach: 8.7 Million Customers Affected. Here Is What To Do

Manchester Airport logo, illustrating the August 2026 Manchester Airports Group data breach
Published: September 12, 2026

If you have ever booked parking, a lounge or Fast Track at Manchester Airport, or signed up for the free Wi-Fi in the terminal, there is a good chance your details are now in the hands of criminals. The Manchester Airport data breach is one of the largest the UK has seen this year.

We know because it happened to us. Like millions of others, QLine IT received an email from Manchester Airports Group telling us that the address we used to book airport parking was among the data taken. This article explains what happened, what the criminals now hold, and the practical steps you and your staff should take.

What happened?

On 27 August 2026, Manchester Airports Group (MAG), which owns Manchester, London Stansted and East Midlands airports, confirmed that hackers had accessed customer data over the previous weekend. Around 8.7 million customers were affected. The BBC covered the story on the day it broke: Hackers steal data from millions of UK airport customers.

The hackers demanded a ransom. MAG refused to pay, which is the right call and the advice of the National Crime Agency, but it had a consequence. On 2 September the criminals published the entire database online for anyone to download. The BBC reported that too: Criminals publish data of 8.7m people after Manchester Airports Group hack.

The data was taken from the systems behind car park bookings, lounge and Fast Track purchases and in-airport Wi-Fi sign-ups. According to MAG’s own data security incident page, it includes:

  • Email addresses
  • Phone numbers
  • Vehicle registration numbers
  • Postcodes

Analysis of the published files by the breach-tracking service Have I Been Pwned found more than that. The leaked records also contain names, purchase history, IP addresses and browser details. MAG says no bank or payment card details were held on the affected system, and that airport operations and passenger safety were never at risk.

Why this matters, even without card details

People tend to relax when they hear “no payment details were taken”. Do not. The criminals do not need your card number. They have something more useful: a set of true facts about you that they can use to sound convincing.

Think about what a scammer can now say to you:

  • “We are calling from Manchester Airport about your parking booking for vehicle [your real registration].”
  • “Your Fast Track purchase needs re-confirming, click here.”
  • “There is a problem with your booking. To keep it, confirm your card details.”

Every one of those messages will contain details only the real airport should know. That is what makes this breach dangerous. The data is also on the open internet, not hidden on the dark web, so it is easy for any scammer to get hold of.

For businesses there is a second problem. Booking history shows where people have travelled and when. If your staff booked parking with a work email address, that address, their phone number and their travel pattern are now linked together and public.

How to check if you are affected

MAG says it has contacted everyone affected directly by email. If you have not had an email, that does not prove you are safe. Check for yourself:

  1. Go to Have I Been Pwned and enter your email address. The Manchester Airports Group breach was added on 2 September 2026 and shows 8.8 million accounts.
  2. Check every address you might have used, including old personal addresses and work addresses.
  3. If you run a business, ask your staff to check their work addresses too.

What you should do right now

Nothing in this breach can be undone. You cannot change your postcode or your number plate. What you can do is make the stolen data useless to a scammer.

Treat every unexpected message about airports, parking or travel as suspicious. MAG has said plainly that it will never contact you unexpectedly to ask for card details, banking information or passwords. If you get a call or message like that, hang up or delete it. If you think it might be genuine, go to the airport’s website yourself and contact them through it. Never use a link or number from the message.

Report scam messages. Forward suspicious emails to report@phishing.gov.uk, the National Cyber Security Centre’s reporting service. Forward scam text messages to 7726, which is free on all UK networks.

Turn on multi-factor authentication. Your email address is now on a list criminals are actively working through. If that address is the login for your email, Microsoft 365, banking or anything else, a password alone is no longer enough. We explain how in our guide to multi-factor authentication.

Change any password you have reused. Passwords were not part of this breach, but criminals routinely combine leaked email addresses with password lists from older breaches. If the password on your email account is one you have used anywhere else, change it now.

Watch your bank statements and credit report. The Information Commissioner’s Office has step-by-step advice for people affected by a data breach. It recommends checking statements for unusual activity and reporting any stolen document details to the issuer.

Tell your staff. A single email to your team saying “this happened, here is what a scam might look like, do not click” will stop most of the damage. Scammers rely on people not having been warned.

What can we learn from this?

MAG is a large organisation with a security budget most businesses could only dream of, and it was still caught out. The criminals claim they did not need to break anything. They say they found access keys sitting in the public code of the airports’ websites, unchanged for years, and simply used them.

The lesson for every business is the same one we repeat to our own clients:

  • Know where your credentials and keys live, and rotate them. A key that has not changed in four years is a key someone else probably has.
  • Collect only the data you need, and delete it when the need has passed. A Wi-Fi sign-up form did not need to keep millions of email addresses forever.
  • Assume a breach will happen and plan the response before it does. MAG contained the incident quickly and told people. Many businesses could not do either.
  • Train your people. In the end, the stolen data only makes money for criminals when someone acts on a convincing message.

IT Solutions

If you are not sure whether your business is exposed, or you want help rolling out multi-factor authentication and staff awareness training before the scam messages start arriving, speak to QLine IT. We are Cyber Essentials Plus accredited and we help businesses across Leeds and the UK turn news like this into a checklist rather than a crisis.

IT Solutions

Whatever your IT needs, we have the expertise to deliver a managed solution to keep your hardware and software optimised for your workflow.

QLine IT icon

Recent Case Study:

More News…

Person at a desk reviewing a business dashboard with charts, with QLine IT teal and orange brand colours

AI in Business: What It Actually Does, and Where the Hours Are Saved

For a lot of business owners, artificial intelligence sits in an uncomfortable place. It is clearly important, everyone says so, and yet the practical question of what to do about it on a Monday morning goes unanswered. The coverage tends to swing between...

QLine IT - logo TM
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.