WEDNESDAY, SEPTEMBER 2, 2026|No. 13601
Cybersecurity · Aviation

UK Airports Hack Exposes Personal Data of Millions

A significant cybersecurity incident at three UK airports has resulted in the public release of personal data belonging to nearly nine million individuals.

A digital representation of airport security systems and data flow.
A digital representation of airport security systems and data flow.
1 sources
Pipeline ingest
3 reads
Positive / Neutral / Negative
1 countries
Related coverage

Criminal hackers have posted the personal data of nearly nine million people online after breaching three UK airports.

Hackers tried to extort Manchester Airports Group (MAG) for an undisclosed amount but failed to get their ransom paid.

Customers of Manchester, London Stansted and East Midlands airports are being warned of secondary attacks as the data is now available to other criminals.

"MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support," the company said in a statement.

"We are continuing to work with the authorities and specialist advisors. Neither MAG nor the system accessed hold customers' bank or payment details," it added.

Contact details, vehicle registrations and postcodes were stolen in the breach that appears to have accessed databases containing wi-fi log in and car parking details.

The cyber-crime group - which the BBC is not naming - is offering the entire data set for free to other criminals or scammers through their website.

"Today we are releasing the Manchester Group database," they wrote.

"Half a terabyte, and every byte of it is pure PII [personally identifiable information]."

Risk of future scams

Stolen data experts at HaveIBeenPwned have analysed the published data and confirmed that it contains people's email addresses, phone numbers, addresses, licence plate numbers, purchasing history and browsing device data.

Cyber-security expert Kevin Beaumont warned those affected to be on high alert for other forms of scam and hack - especially high profile or wealthy individuals.

"The data includes both historical locations and planned future travel, so individuals sensitive to their movements being known may need to take precautions," he said.

"People should be alert to scammers reusing the data and so knowing details such as phone numbers and car registration numbers," he added.

"Our advice to affected customers remains to be vigilant for unsolicited emails, text messages and phone calls," MAG said in its statement.

"We would like to reassure customers that Manchester Airport Group takes the security of customer information extremely seriously and we apologise for any inconvenience or concern caused."

At no point was passengers' physical safety at risk in the airports, the company said after the breach.

Unusually, the cyber criminals' website where the MAG data is available is hosted on the clear internet and not on the dark net like most other so-called hacker "leak sites".

This makes the data easier to access, increasing the risk to victims of MAG and the other companies the gang has breached in recent months.

As well as posting the stolen data, the hackers boasted about how they breached each victim using the same method each time - exploiting weaknesses in how companies store their digital keys for internal networks.

What if my information has been taken?

Data watchdog the Information Commissioner's Office has advice on its website for people whose data has been hacked. It includes:

  • Report any details of stolen documents including passports, credit cards or driver's licences to the issuer
  • Check your bank statement and credit report for any unusual activity
  • Keep alert for any suspicious emails, messages or phone calls
  • Use strong passwords and multi-factor authentication for online accounts

PAN's pipeline reviewed approximately 1 open sources for this article. No human editor reviewed this article before publication.

Related Reads

Show on timeline →