Cyberattack in Manchester: 8.7 Million Travelers Compromised by Free Airport Wi-Fi
Forced stop in cybersecurity. Manchester Airports Group, the operator of Manchester, London Stansted, and East Midlands airports, acknowledged on Thursday, August 27, that an intruder had accessed its customer databases. No flights were canceled, no runways blocked, but millions of email addresses, phone numbers, and license plates are now exposed. The entry point is rather concerning: the registration forms for free Wi-Fi and parking reservations. Yet another data leak affecting a public service in daily life, and not the most glamorous one.
Key points of this article:
- Manchester Airports Group has acknowledged a massive data leak affecting millions of customers, via Wi-Fi forms and parking reservations.
- Approximately 8.7 million customers may have been exposed, making this leak ripe for phishing, although no banking data has been compromised.
The group issued its official statement on August 27, late in the morning. The text is straightforward. An unauthorized third party obtained a quantity of customer data related to parking reservations, lounges, and priority passage (the famous Fast Track), as well as Wi-Fi registrations at the airports. The data involved includes email addresses, phone numbers, vehicle registrations, and postal codes.
Nothing banking-related, insists MAG. Indeed, the affected system does not store payment details or card numbers. Aviation security has not been impacted, flights are taking off, operations are running smoothly. The group claims to have immediately contained the risk, called in external specialists, and notified the relevant authorities. The online service Manage My Booking has nonetheless been suspended during the investigation.
To put it in perspective, the three platforms of Manchester Airports Group see over 66 million passengers annually. A hastily filled Wi-Fi form between two boarding gates, multiplied by years of operation, ends up constituting a respectable directory. And that is precisely what someone has just taken.
8.7 million customers: a data leak tailored for phishing
MAG's statement does not provide any figures. It was The Record, on August 27, that quantified the incident, estimating around 8.7 million affected customers. A spokesperson for the group, quoted by the Yorkshire Post, tempered this: in the vast majority of cases, the only information accessed would be an email address. The rest, phone number, license plate, and postal code, mainly concerns customers who reserved a parking space or access to lounges.
However, it is precisely this minority that poses a problem. An email address alone is just spam. An email address associated with a license plate, a postal code, and a parking stay date at Stansted is a ready-to-use kit for a fake parking refund or a bogus parking fine, sent at the right time to the right person.
Phishing (the art of impersonating a legitimate organization to extract credentials or payments) loves this kind of precision. MAG has also warned its customers via email to remain vigilant against suspicious messages. The irony of receiving an alert email about fraudulent emails will not be lost on anyone.
No ransomware group had claimed responsibility for the attack by Thursday evening. The details of the intrusion also remain unclear. The group refers to a sophisticated attack rather than human error, a classic phrase in such statements, to be taken with the usual caution.
The aviation sector has been collecting incidents for two years. In September 2025, a ransomware attack against Collins Aerospace, a supplier of registration systems for many European airports, paralyzed the counters at Heathrow, Brussels, Berlin, and Dublin for several days. Passengers were checking in manually, with luggage tags written by hand. A year earlier, Seattle-Tacoma Airport had seen its screens and websites fall victim to the Rhysida group, which demanded 100 bitcoins in ransom to return the data.
The difference with Manchester is that nothing stopped. No one noticed the outage. This is the silent version of the problem, the one that does not make the headlines, but fuels months of scam campaigns. Airports may fortify their air traffic control systems, but they drag behind them dozens of commercial applications (parking, lounges, Wi-Fi, shops) that are much less monitored and often hosted by third-party providers. The chain breaks where it is thinnest.
On the regulatory side, the matter lands on the desk of the ICO, the UK data protection authority. The precedent exists and it is painful: in October 2020, the ICO fined British Airways £20 million for a leak affecting 400,000 customers, a record penalty at the time in the UK. With 8.7 million people affected, MAG is playing in a different league.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

U.S. Military Maintenance Backlog Exceeds $285 Billion

BCRA purchases exceeded $14 billion barrier in 2026

BlackRock's iShares Bitcoin Trust ETF regains weekly options expiries

Crypto XRP: Evernorth Moves Closer to Wall Street and Nasdaq

Anthropic Plans to Allow Shareholders to Sell Shares in IPO

BTC Transfer from Kraken: 843 Bitcoins Leave the Exchange to Unknown Wallet

$6.4 Billion in Bitcoin Options Expire Tomorrow—Here's What It Means

DEBIT Airdrop Guide: How to Share 50,000 USDT Rewards on WEEX

What is Bitlayer (BTR)? What Happened with Bitcoin Bridge?

How to Have Internet Abroad Without Spending Hundreds of Dollars: The Difference Between eSIM and Roaming

Chrome and Chromium Test Flatpak to Expand Their Reach on Linux

Ethereum Excites Me More Than Bitcoin: Interesting Situation on the Chart and ETF Fund Data

Swvl Raises $13 Million Led by Coefficient Backed by the Sawiris Family

Controversial Influencer Launches Meme Coin, Hype Fades Quickly

Ethereum Trader Returns: Buys $5.33 Million After $12 Million Loss

AI is in a Credit Expansion Phase: The Stronger AI Becomes, the More the Federal Reserve Needs to Cut Rates

Chinese Naval Activity Near Taiwan Sets Record for Third Consecutive Month

Hawk Fire Forces Evacuation of 90,000 People Near Reno

Institutional Cryptocurrency Trading Reaches Record 72%: Major Players Smooth Market Volatility

Solana Burn Surges to 87,000 SOL: Does This Change Token Scarcity?

Cryptocurrency Exchange in Russia: Top 3 Services for 2026

Top 20 Cryptocurrencies: New Market Leaders and the Battle for Infrastructure

The US approved high-leverage Bitcoin trading while crypto founders remain legally blocked from raising funds

Central Bank Explains Cryptocurrency Exchange for Russian Securities

Hacker Who Leaked GTA 6 Created a Coin, Soared 20 Times in a Day

CVM Brings Tokenization Agenda to NYSE, Nasdaq, and SEC

Russia Strikes 'Aurora' Distribution Center Twice

On-Chain Analysis Tools for Cryptocurrencies: How to Read SSR and Stablecoin Capitalization

Ethereum Accelerates Work on zkEVM Security Ahead of December Deadline









