ctipilot.ch
← Back to the live brief
HIGHNATOA2incident

Manchester Airports Group confirms a breach touching roughly 8.7 million customers across Manchester, Stansted and East Midlands — car-park, lounge and airport-WiFi sign-up data taken, no operational or payment-card impact, no actor named

first published 2026-08-28 06:10 UTCrun 2026-08-28T0409Z-intel3 sourcesmulti-source

Manchester Airports Group (MAG), operator of Manchester, London Stansted and East Midlands airports, confirmed on 2026-08-27 that "an unauthorised third party" obtained "a quantity of customer data" relating to car-park, lounge and Fast Track bookings and in-airport WiFi sign-ups (Manchester Airports Group, 2026-08-27). Roughly 8.7 million customers are affected, the large majority with only an email address exposed — collected during public-WiFi signup: "the overwhelming majority of those affected have only had their email addresses compromised" (The Register, 2026-08-27) — a smaller subset also had phone numbers, vehicle registrations and postcodes taken.

MAG states neither it nor the accessed system holds bank or payment-card data, and that no operational or aviation-security system was touched: "at no point has passenger safety or aviation security been compromised" (Manchester Airports Group, 2026-08-27). The group has suspended its Manage My Booking self-service portal as a precaution while investigating. The Register reports — attributed to the outlet, not confirmed by MAG's own statement — that the intrusion compromised one internal system and then pulled files from a third-party-hosted database, that the attacker's ransom demand was notably lower than the group's typical extortion demand and was not paid, and that MAG characterises the incident internally as "a hack, not a lapse." No extortion group or actor has claimed the incident publicly at time of writing, and neither MAG nor any outlet has named an access vector, an exploited product, or a CVE. The UK ICO has confirmed receipt of a breach report and is assessing it.

Technique mapping is deliberately thin: MAG's own statement and every outlet checked confirm the breach and its scale but none states an access vector, exploited product or CVE, and no extortion actor has claimed responsibility. T1213 (Data from Information Repositories) is offered only as a minimal defensible outcome-mapping — data was obtained from an internal system and a third-party-hosted database per The Register's reporting — not as an access-vector claim. As one of Europe's largest airport-group operators and with transport as an additional sector for this constituency, the transferable point is scale rather than mechanism: a breach touching 8.7 million records through what appears to be low-sensitivity WiFi-signup collection illustrates how ancillary customer-facing services (guest WiFi, parking bookings) can carry disproportionate downstream exposure relative to their apparent sensitivity.

Manchester Airports group has been subject to a cyber security incident by an unauthorised third party. A quantity of customer data has been obtained that relates to car park, lounge and Fast Track bookings and in-airport WIFI sign-ups at Manchester, Stansted, and East Midlands airports.

At no point has passenger safety or aviation security been compromised.

Manchester Airports Group

The overwhelming majority of those affected have only had their email addresses compromised.

The Register 2026-08-27

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.2

Collection TA0009
T1213Data from Information Repositories

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.