Manchester Airports Group (MAG) confirmed on Thursday, August 27, 2026, that a cyberattack by an “unauthorised third party” exposed customer data tied to Manchester Airport, London Stansted Airport and East Midlands Airport, affecting approximately 8.7 million customers. The company says flight operations and passenger safety were never disrupted, and that no bank or payment card details were accessed. The story escalated on September 2-3, 2026, when a group calling itself FulcrumSec published the stolen records on its dark web leak site after MAG refused to pay the ransom it had demanded, telling BleepingComputer it had taken approximately 86 GB of compressed data — equal to roughly 640 GB once extracted, a figure SecurityWeek separately put at around 550 GB uncompressed — turning a contained disclosure into a live, public exposure that Have I Been Pwned logged on September 2, 2026 as affecting approximately 8.8 million email addresses. The incident is the second major cyberattack to hit UK and European aviation infrastructure in under a year, following the September 2025 ransomware attack on Collins Aerospace’s check-in software that grounded systems at Heathrow, Brussels and Berlin.
The breach was first reported by LBC, Yahoo News UK and cybersecurity trade press including Hackread and Cybersecurity Insiders, all citing MAG’s own disclosure statement, and the September leak-site publication was subsequently confirmed by BBC and BleepingComputer. What follows is what’s confirmed so far, what remains unknown, and how this incident stacks up against the aviation sector’s recent run of cyber trouble.
Don't miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
MAG Confirms Cyberattack Affecting 8.7 Million Customers
Manchester Airports Group, the operator behind three of England’s busiest airports, disclosed the incident in a statement carried by multiple UK outlets on August 27, 2026. According to that statement, MAG “has been subject to a cyber security incident by an unauthorised third party,” a phrasing companies typically use when they want to describe an intrusion without yet confirming whether it involved ransomware, extortion, or simple data exfiltration.
The scale is what makes this story land: 8.7 million customer records is a bigger exposure figure than most UK data breaches disclosed this year, and it touches a company that isn’t publicly traded, isn’t used to fielding regulatory or shareholder scrutiny at this volume, and runs infrastructure that 65 million passengers a year pass through. MAG is privately owned, split between Manchester City Council (35.5%), nine other Greater Manchester local authorities (29% combined), and Australian infrastructure investor IFM Investors (35.5%), so there’s no stock ticker to watch for a market reaction the way there might be after a breach at a listed company.
Which Airports Were Hit: Manchester, Stansted and East Midlands
All three of MAG’s airports are implicated in the breach: Manchester Airport, London Stansted Airport, and East Midlands Airport. Together they form one of the largest airport groups in the UK by passenger volume, and the exposure appears to be tied to shared customer-facing systems rather than airport-specific infrastructure, which is why all three show up in the same disclosure rather than one airport reporting an isolated incident.
| Airport | Latest Annual Passengers (FY24) | Role in MAG Group | Confirmed in Breach |
|---|---|---|---|
| Manchester Airport | 28.8 million | Largest hub, MAG headquarters | Yes |
| London Stansted Airport | 28.5 million | Second-largest, London low-cost hub | Yes |
| East Midlands Airport | 4.0 million | Passenger and UK’s largest pure-cargo airport | Yes |
| MAG Group Total | 61.3 million | Combined FY24 passenger volume | N/A |
Manchester alone crossed the 30-million-passenger mark on a rolling 12-month basis in late 2024, and Stansted logged its busiest calendar year on record with 29.76 million passengers in 2024. That growth trajectory is part of why a breach here carries weight beyond the immediate 8.7 million figure: these are airports handling record traffic, with record volumes of customer accounts, bookings and loyalty sign-ups sitting in their systems.
Timeline: How the Breach Has Unfolded
Tuesday: Internal Discovery
Per reporting cited by Yahoo News UK, MAG says it became aware of the incident on Tuesday of this week. The company has not published an exact intrusion date, meaning the attacker may have had access to systems for some period before detection — a gap that is typical in data-breach disclosures and one regulators tend to probe closely during any ICO assessment.
Thursday: Public Disclosure
MAG went public with the breach on Thursday, August 27, 2026, telling customers via email that their data had been accessed and that “there is no action you need to take,” according to reporting from Yahoo News UK. The company says it is notifying affected customers directly and working with external cybersecurity specialists and relevant authorities.
Thursday, September 3: Data Published on a Leak Site
One week after MAG’s initial disclosure, a group calling itself FulcrumSec posted the stolen records to its dark web leak site and told BleepingComputer it had extracted approximately 86 GB of compressed data, equal to roughly 640 GB once unpacked. BBC subsequently reported that the publication put the same 8.7 million customers MAG had already notified at heightened risk of follow-on scams, since the data was no longer confined to a single criminal group’s private server.
- Tuesday, Aug 25, 2026 (per MAG statement): MAG becomes aware of unauthorised access to customer data systems.
- Aug 25–27, 2026: MAG engages cybersecurity specialists and begins containment.
- Thursday, Aug 27, 2026: Public disclosure; customer notification emails sent; UK outlets report the story.
- Thursday, Sept 3, 2026: FulcrumSec publishes the stolen data on its leak site, claiming approximately 86 GB compressed (roughly 640 GB extracted); BBC and BleepingComputer confirm the publication.
- Ongoing: No individuals tied to FulcrumSec have been named, arrested or charged; no ICO enforcement action confirmed.
What Data Was Stolen — And What MAG Says Was Not
According to MAG’s own statement, the exposed data relates to car park bookings, airport lounge access, Fast Track security bookings, and in-airport Wi-Fi sign-ups across the three airports. The categories of personal information involved include email addresses, phone numbers, vehicle registration numbers and postcodes. Critically, MAG says the “vast majority” of accessed records contained nothing more sensitive than an email address, and the company has stated explicitly that no bank details or payment card information were accessed.
That distinction matters for how the incident gets classified. A breach limited to contact details and vehicle registration numbers is serious — vehicle plates combined with postcodes and email addresses is enough raw material for targeted phishing — but it’s a materially different risk profile than a breach involving card numbers, passport data or passwords. No evidence has been reported that login credentials, passport numbers or boarding-pass data were part of the exposure.
- Email addresses: confirmed accessed (majority of records).
- Phone numbers: confirmed accessed.
- Vehicle registration numbers: confirmed accessed (car park bookings).
- Postcodes: confirmed accessed.
- Bank or card payment details: not accessed, per MAG.
- Passport or ID numbers: not reported as accessed.
- Account passwords: not reported as accessed.
Inside the 8.7 Million Number
The 8.7 million figure comes directly from MAG’s disclosure and represents customer records tied to car park, lounge, Fast Track and Wi-Fi services across all three airports, not 8.7 million unique passengers with equally sensitive data exposed. Given that MAG’s three airports collectively serve around 61 million passengers a year, a chunk of these records likely reflect repeat customers, multi-year booking histories, and one-time Wi-Fi sign-ups rather than 8.7 million distinct individuals hit with the same severity of exposure. Still, it’s a headline number that puts this incident in the same conversation as some of the UK’s largest reported consumer data breaches this year. After the September 2-3 leak-site publication, BBC described the same population as nearly nine million people whose data was now public, framing the leak as a heightened risk of secondary attacks rather than a change in the underlying scale of the breach — a reading reinforced when Have I Been Pwned added the incident to its database on September 2, 2026, listing it as affecting approximately 8.8 million email addresses, a figure that closely tracks, and slightly exceeds, MAG’s own 8.7 million count.
What Manchester Airports Group Is Telling Customers
MAG has issued several public statements since the disclosure. On the nature of the incident, a company spokesperson said: “Manchester Airports Group has been subject to a cyber security incident by an unauthorised third party.”
On what was taken, the spokesperson said: “A quantity of customer data has been obtained that relates to car park, lounge and Fast Track bookings and in-airport WIFI sign-ups at Manchester, Stansted and East Midlands airports.”
On the company’s response, MAG said: “We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems.”
MAG has also moved to reassure travellers about operational safety, stating: “At no point has passenger safety or aviation security been compromised.” And on the severity of what was actually exposed for most people affected, the company told The Record: “In the vast majority of cases, the only information accessed was an email address.”
FulcrumSec Claims the Attack and Publishes the Data
That quieter phase ended on September 2-3, 2026. A group calling itself FulcrumSec published the stolen Manchester Airports Group records on its dark web leak site, telling BleepingComputer it had extracted approximately 86 GB of compressed data — equal to roughly 640 GB once decompressed, a figure SecurityWeek reported separately as roughly 550 GB uncompressed. Both BBC and SecurityWeek reported that FulcrumSec had in fact demanded a ransom and that MAG refused to pay it, which is what triggered the leak-site publication rather than a private, unresolved extortion standoff. That’s a meaningfully different posture than the Collins Aerospace incident a year earlier, where the disruption was immediate and visible (grounded check-in kiosks, manual boarding) even before attribution became clear. Here, the “unauthorised third party” language and the absence of operational disruption pointed to a quieter data-exfiltration event — and the FulcrumSec publication is the monetization attempt that pattern predicted, consistent with double-extortion groups that steal data first and threaten, or proceed, to leak it second.
No individuals have been named, arrested, or charged in connection with FulcrumSec or the incident more broadly. Law enforcement involvement has been described only in general terms — MAG says it is “working with cyber security specialists and the relevant authorities” — without specifics on which agencies are leading a criminal investigation.
Inside the FulcrumSec Numbers: What 86 GB Compressed Really Means
The figures FulcrumSec gave BleepingComputer are worth unpacking, because compressed and extracted file sizes tell different stories about scope. The group said it stole approximately 86 GB of compressed data, then said that figure expands to roughly 640 GB once extracted — a ratio of roughly 7-to-1, typical of structured, text-heavy data like databases, spreadsheets and booking records rather than already-compressed formats like images or video. Other outlets tracking the leak arrived at broadly similar totals: SecurityWeek put the uncompressed dump at roughly 550 GB, and breach-monitoring service BreachSense independently indexed the leak at 549 GB as of its most recent check in September 2026 — figures close enough to BleepingComputer’s 640 GB estimate to suggest the discrepancy is a measurement-methodology gap rather than a dispute over scope. That ratio lines up with MAG’s own account of what was taken: car park bookings, lounge access records, Fast Track bookings and Wi-Fi sign-ups are exactly the kind of structured records that compress efficiently, which reinforces MAG’s version of events even as the volume figure adds a new, harder data point to it.
The shift from “stolen” to “published” changes the practical risk calculus for the 8.7 million people affected. Data sitting unreleased on a criminal server mainly threatens the original victim — MAG faces potential extortion and reputational damage, while the individuals whose records were taken face a comparatively lower near-term risk as long as the data stays private. Once that same data is posted to a leak site, it becomes accessible to any other criminal willing to download it, a population far larger and less predictable than a single extortion crew. That is the distinction BBC drew in reporting that criminals had published the personal data of nearly nine million people online, framing the leak as a material increase in the risk of secondary attacks — targeted phishing, vehicle-registration scams and identity-fraud attempts — against the same 8.7 million customers MAG first disclosed in August.
For MAG, the publication also narrows the window in which “no fine or enforcement action has been reported” is likely to hold. UK GDPR guidance treats a confirmed, public leak more seriously than a contained internal breach, in part because publication removes any ambiguity about whether the data has left the organisation’s control. Regulators weighing a proportionate response — and courts assessing any future compensation claims — are now looking at a data set that is objectively downloadable, rather than one whose external exposure was, until September 3, unconfirmed.
How This Compares to the 2025 Collins Aerospace Airport Attack
The clearest recent point of comparison is the September 2025 ransomware attack on Collins Aerospace’s MUSE check-in and boarding software, which disrupted operations at Heathrow, Brussels, Berlin and other European airports. The UK’s National Cyber Security Centre (NCSC) confirmed it was working with Collins Aerospace, the affected airports, the Department for Transport, and law enforcement on that incident, and later analysis linked the intrusion to the HardBit ransomware family, according to reporting summarized on Wikipedia and covered in depth by CNBC.
The two incidents differ in almost every way except the sector they hit. Collins Aerospace’s breach caused visible, immediate operational chaos — queues, cancelled flights, manual check-in — because it hit third-party software that airports depend on to process passengers. The MAG breach, by contrast, hit customer data systems (parking, lounges, Wi-Fi) without touching flight operations at all. One is an availability attack with a data question mark; the other is a confidentiality breach with no reported availability impact. That gap narrowed slightly on September 3, when FulcrumSec’s leak-site publication turned MAG’s breach from a private, single-actor confidentiality incident into a public one — though it still has produced none of the flight delays, cancellations or manual check-in chaos that defined the Collins Aerospace attack.
| Factor | MAG Breach (Aug 2026) | Collins Aerospace / MUSE Attack (Sept 2025) |
|---|---|---|
| Airports affected | Manchester, Stansted, East Midlands (UK) | Heathrow, Brussels, Berlin and others (Europe) |
| Primary impact | Customer data confidentiality | Operational disruption (check-in/boarding) |
| Passenger safety impact | None reported | None reported |
| Ransomware confirmed | Not confirmed; FulcrumSec claims data theft, not encryption | Confirmed; later linked to HardBit |
| Records/scope disclosed | 8.7 million customer records | Not primarily a data-volume story |
| Government body involved | Unspecified “relevant authorities” | NCSC, UK Department for Transport, law enforcement |
| Attribution | Claimed by FulcrumSec (leak published Sept 3, 2026) | Later linked to HardBit ransomware group |
Taken together, the two incidents inside 12 months point to a pattern: aviation infrastructure, whether it’s shared check-in software or a regional airport group’s customer database, is now a standing target for both ransomware crews chasing operational leverage and data thieves chasing bulk personal information they can resell or use for phishing.
The Regulatory Clock: ICO, UK GDPR and What Could Follow
Because the exposed data includes personal information — email addresses, phone numbers, vehicle registration numbers and postcodes — this breach falls squarely within the scope of UK GDPR’s personal-data breach rules. Organisations that suffer a breach affecting personal data generally must notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware, where the breach is likely to result in a risk to individuals’ rights and freedoms. Neither MAG nor the reporting so far confirms whether the ICO has opened a formal investigation, but the size of the affected population — 8.7 million records — makes ICO engagement highly likely given the regulator’s own disclosure thresholds.
No fine or enforcement action has been reported at the time of publication. UK GDPR fines can theoretically reach up to £17.5 million or 4% of global annual turnover, whichever is higher, though actual penalties for breaches involving contact details rather than financial or special-category data have historically landed well below that ceiling. British Airways’ 2018 breach, which involved payment card data, drew a reduced ICO fine of £20 million after an initial proposal of £183 million — a reminder that headline maximum fines and final settlements in UK data-breach cases are rarely the same number.
Business and Market Fallout for MAG
Because MAG is privately owned by Manchester City Council, other Greater Manchester local authorities, and IFM Investors rather than publicly traded, there’s no share price to move and no earnings call where analysts will grill executives on breach costs next quarter. That doesn’t mean there’s no financial exposure: MAG does issue public debt instruments to investors, and rating agencies covering that debt typically factor operational and reputational risk from incidents like this into their credit assessments. Notification costs, forensic investigation fees, potential ICO penalties, and the cost of any compensation claims from affected customers all sit on MAG’s own balance sheet rather than being absorbed by public shareholders.
MAG has stated the breach caused no operational disruption, meaning parking, lounge access and terminal operations continued as normal through the disclosure. That’s a meaningful contrast to Collins Aerospace’s 2025 incident, which produced direct, quantifiable costs for airlines and airports in the form of flight delays, cancellations and rebooking expenses. The financial fallout from the MAG breach, by comparison, is likely to be concentrated in remediation, regulatory response and any downstream legal claims rather than immediate operational losses. That calculus shifted after September 3: once data central to a breach is confirmed published rather than merely stolen, remediation and legal-claims costs tend to move from theoretical to concrete, since affected customers and regulators now have a verifiable public leak to point to rather than an internal company disclosure alone.
Why Airports Are Becoming a Preferred Ransomware and Data-Theft Target
Airports sit at an unusual intersection: they’re critical infrastructure, they process enormous volumes of personal and payment data through parking, retail, lounges and Wi-Fi, and they typically run a patchwork of legacy systems alongside newer customer-facing platforms built by third-party vendors. That combination — high-value data, high public visibility, and fragmented IT estates — makes them attractive to two different kinds of attackers: ransomware crews looking for operational leverage they can use to extort a fast payout, and data thieves looking for bulk personal records they can sell or weaponize for phishing campaigns.
The Collins Aerospace attack showed how a single shared vendor platform can cascade disruption across multiple airports and countries at once. The MAG breach shows the other failure mode: a regional operator’s own customer database, spanning parking, lounges and Wi-Fi sign-ups across three sites, becomes a single point of exposure for millions of records the moment one system is compromised. Both incidents point toward the same underlying issue that cybersecurity analysts have flagged repeatedly around aviation: the sector has consolidated its digital infrastructure faster than it has consolidated its security posture.
What Affected Customers Should Do Right Now
MAG’s own guidance to customers, per its notification emails, is that “there is no action you need to take.” That’s consistent with the nature of the exposed data — email addresses, phone numbers, vehicle registrations and postcodes don’t give attackers direct access to bank accounts or passwords. That guidance predates the September 3 leak-site publication, and the underlying advice hasn’t changed, but the case for following it has gotten stronger now that the data is confirmed public rather than held by a single group. Standard precautions apply for anyone who used car park, lounge, Fast Track or in-airport Wi-Fi services at Manchester, Stansted or East Midlands airports recently:
- Treat unsolicited emails or texts referencing airport parking, lounge bookings or Fast Track services with suspicion, especially any asking for payment details or login credentials.
- Do not click links in messages claiming to be from MAG unless you can verify the sender address matches official MAG or airport domains.
- Change passwords on any account where you reused the same password used for airport booking services, even though MAG says passwords were not part of the exposure.
- Watch for vehicle-related scams, since registration numbers were among the exposed data categories and could be used in convincing-looking parking-fine or toll-related phishing attempts.
- Report suspicious messages referencing this breach to Action Fraud, the UK’s national reporting centre for fraud and cybercrime.
What Happens Next: Predictions
Based on how comparable UK breaches have played out and the facts confirmed so far, here’s how this story is likely to develop over the coming weeks:
- ICO scrutiny is highly likely — and more urgent after September 3. Given the confirmed 8.7 million figure and the FulcrumSec leak-site publication, expect the ICO to at minimum open a formal assessment of MAG’s breach-notification process and security controls, even if no fine follows immediately.
- Secondary phishing and fraud attempts will likely rise. Now that FulcrumSec has published the data rather than holding it privately, expect more phishing emails, vehicle-registration scams and impersonation attempts referencing MAG, Manchester, Stansted or East Midlands bookings in the weeks following the leak.
- Customer notification and monitoring costs will be the first hard cost MAG absorbs, regardless of whether a regulatory fine ever materializes, given the scale of the affected population and the confirmed public exposure of their data.
- Other UK airport operators will face pressure to publish security assurances, following two major aviation-sector incidents within a 12-month window, and the NCSC is likely to issue renewed sector-wide guidance similar to what it published after Collins Aerospace.
- Legal claims from affected customers become more plausible now that the data is public, since a confirmed leak-site posting gives claimants a more concrete basis for showing risk or distress than an unconfirmed internal breach would.
Frequently Asked Questions
Which airports were affected by the Manchester Airports Group breach?
Manchester Airport, London Stansted Airport and East Midlands Airport — all three airports operated by Manchester Airports Group — were affected, according to MAG’s own disclosure.
How many customers were affected by the MAG data breach?
MAG says approximately 8.7 million customer records were accessed, tied to car park, lounge, Fast Track and in-airport Wi-Fi sign-up data across the three airports.
Was payment or bank data stolen in the Manchester Airport breach?
No. MAG has stated that bank details and payment card information were not accessed. The exposed data is limited to email addresses, phone numbers, vehicle registration numbers and postcodes.
Was this a ransomware attack?
MAG initially described it only as a cyber security incident carried out by an “unauthorised third party.” That changed on September 2-3, 2026, when a group calling itself FulcrumSec published the stolen data on its dark web leak site, claiming to have extracted approximately 86 GB of compressed data (roughly 640 GB unpacked, or about 550 GB per SecurityWeek’s separate estimate). No specific ransom demand amount has been disclosed, but BBC and SecurityWeek both reported that MAG refused to pay before FulcrumSec published the data, and Have I Been Pwned subsequently added the breach to its database on September 2, 2026, listing it as affecting approximately 8.8 million email addresses.
What is FulcrumSec and what did it publish?
FulcrumSec is the group that published the stolen Manchester Airports Group data on its dark web leak site on September 3, 2026. It told BleepingComputer it had taken approximately 86 GB of compressed data, equal to roughly 640 GB once extracted, covering the same car park, lounge, Fast Track and Wi-Fi records MAG disclosed in August. No individuals tied to the group have been named, arrested or charged.
Did the breach disrupt flights at Manchester, Stansted or East Midlands airports?
No. MAG says the incident has not resulted in any operational disruption, and that passenger safety and aviation security were not compromised at any point.
Is this related to the Collins Aerospace airport cyberattack in 2025?
No connection has been reported. The September 2025 Collins Aerospace attack targeted check-in and boarding software used at Heathrow, Brussels and Berlin and caused operational disruption, while the MAG breach is a separate incident involving customer data at three different UK airports with no reported operational impact.
What should customers do if they used MAG parking, lounge or Wi-Fi services?
MAG says no action is required, but customers should stay alert for phishing emails or texts referencing airport bookings, avoid clicking unfamiliar links, and report suspicious messages to Action Fraud.
Could Manchester Airports Group face a fine over this breach?
It’s possible but not confirmed. UK GDPR allows the ICO to fine organisations up to £17.5 million or 4% of global turnover for serious breaches, though actual penalties in comparable UK cases have typically landed well below that maximum. No ICO investigation or fine has been confirmed at the time of publication.
- Iran-Linked Hackers Shut UK Power Plant for 4 Days [2026]
- Data Breaches Top 471M Victims in H1 2026 [2026]
- How to Protect Against Ransomware: 13 Steps, 100 Min [2026]
- Cl0p Hits PTC Windchill: CVSS 9.8 Flaw, 43 Victims [2026]
- CISA KEV Adds 4 Critical CVEs, 3 Rated CVSS 9.8 [2026]
- Build an Incident Response Plan: 12 Steps, 90 Min [2026]
- Cybersecurity Threats 2026: Full Coverage


