ctipilot.ch

Manchester Airports Group data breach

incident · incident:manchester-airports-group-data-breach-2026-08

Unauthorised third-party access to roughly 8.7M customer records (car-park, lounge, Fast Track booking and airport-WiFi sign-up data) across MAG's three UK airports, disclosed 2026-08-27; no actor claimed, no access vector confirmed (MAG statement, The Register, 2026-08-27).

Coverage timeline
1
first 2026-08-28 → last 2026-08-28
Peak priority
high
1 high
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-08-28/manchester-airports-group-data-breach-8-7-million · ATT&CK page ↗

Story timeline

  1. 2026-08-28Manchester Airports Group confirms a breach touching roughly 8.7 million customers across Manchester, Stansted and East Midlands — car-park, lounge and airport-WiFi sign-up data taken, no operational or payment-card impact, no actor named
    active-threatsOne of Europe's largest airport-group operators discloses an 8.7M-record breach with no access vector confirmed

Where this entity is cited

  • active-threats1

Source distribution

  • infosecurity-magazine.com1 (33%)
  • manchesterairport.co.uk1 (33%)
  • theregister.com1 (33%)

explore in graph

Entries about Manchester Airports Group data breach (1)

2026-08-28 · view entry permalink →

HIGHNATOA2

Manchester Airports Group confirms a breach touching roughly 8.7 million customers across Manchester, Stansted and East Midlands — car-park, lounge and airport-WiFi sign-up data taken, no operational or payment-card impact, no actor named

Manchester Airports Group (MAG), operator of Manchester, London Stansted and East Midlands airports, confirmed on 2026-08-27 that "an unauthorised third party" obtained "a quantity of customer data" relating to car-park, lounge and Fast Track bookings and in-airport WiFi sign-ups (Manchester Airports Group, 2026-08-27). Roughly 8.7 million customers are affected, the large majority with only an email address exposed — collected during public-WiFi signup: "the overwhelming majority of those affected have only had their email addresses compromised" (The Register, 2026-08-27) — a smaller subset also had phone numbers, vehicle registrations and postcodes taken.

MAG states neither it nor the accessed system holds bank or payment-card data, and that no operational or aviation-security system was touched: "at no point has passenger safety or aviation security been compromised" (Manchester Airports Group, 2026-08-27). The group has suspended its Manage My Booking self-service portal as a precaution while investigating. The Register reports — attributed to the outlet, not confirmed by MAG's own statement — that the intrusion compromised one internal system and then pulled files from a third-party-hosted database, that the attacker's ransom demand was notably lower than the group's typical extortion demand and was not paid, and that MAG characterises the incident internally as "a hack, not a lapse." No extortion group or actor has claimed the incident publicly at time of writing, and neither MAG nor any outlet has named an access vector, an exploited product, or a CVE. The UK ICO has confirmed receipt of a breach report and is assessing it.

Technique mapping is deliberately thin: MAG's own statement and every outlet checked confirm the breach and its scale but none states an access vector, exploited product or CVE, and no extortion actor has claimed responsibility. T1213 (Data from Information Repositories) is offered only as a minimal defensible outcome-mapping — data was obtained from an internal system and a third-party-hosted database per The Register's reporting — not as an access-vector claim. As one of Europe's largest airport-group operators and with transport as an additional sector for this constituency, the transferable point is scale rather than mechanism: a breach touching 8.7 million records through what appears to be low-sensitivity WiFi-signup collection illustrates how ancillary customer-facing services (guest WiFi, parking bookings) can carry disproportionate downstream exposure relative to their apparent sensitivity.

Manchester Airports group has been subject to a cyber security incident by an unauthorised third party. A quantity of customer data has been obtained that relates to car park, lounge and Fast Track bookings and in-airport WIFI sign-ups at Manchester, Stansted, and East Midlands airports.

At no point has passenger safety or aviation security been compromised.

Manchester Airports Group

The overwhelming majority of those affected have only had their email addresses compromised.

The Register 2026-08-27
incident28 Aug 06:10Zmulti-sourceOpen finding ↗