A major cyberattack has been recorded in the United Kingdom, in which attackers gained access to the personal data of approximately 8.7 million customers of Manchester, Stansted and East Midlands airports. The incident was disclosed by operator Manchester Airports Group (MAG) and confirmed by several independent outlets. According to the company, the attack affected systems linked to the airports' additional services, but aviation security and the operation of the terminals themselves were not compromised.

What exactly was affected

According to the disclosed information, the breached system stored data on parking bookings, access to lounge areas, use of "fast-track" corridors, and registration for airport Wi-Fi. As a result, the attackers obtained customers' email addresses, phone numbers, vehicle registration numbers and postal codes. The company stressed that banking and payment data were not stored in the compromised system, which reduces the risk of direct financial losses for those affected.

Operator's response and security status

A representative of Manchester Airports Group stated that the threat was immediately contained, that the company is working with cybersecurity specialists and has informed the relevant authorities. Parking and other customer services continue to operate as normal. At Stansted Airport, affected customers were sent letters recommending they be especially cautious of unexpected calls, letters and messages allegedly coming from the airport: the operator reminded them that it never requests payment or banking details in unsolicited contact — a classic phishing scenario that attackers often exploit after a contact database leak.

Context: peak season and passenger volumes

The attack occurred at the height of the summer tourist season, this week many families are returning to Britain ahead of the start of the school year. For scale: last year, around 54 million passengers passed through the three affected airports combined. Thus, the leak affected a significant share of annual passenger traffic, making the incident one of the largest in the British aviation infrastructure sector in recent times.

Legal and expert assessment

Partner at law firm Gordons, Lauren Wills-Dickson, noted that airports provide a wide range of services — from lounge and parking access to "fast-track" corridors, and connecting to Wi-Fi also requires entering personal data. As a result, operators accumulate vast volumes of customer information, and the growing use of digital technologies only increases the attack surface and the risk of cyber incidents. Experts point out that even without payment data, the leak of contacts and vehicle registration numbers creates fertile ground for targeted fraud campaigns.

Broader cyber threat landscape

The incident occurred against a backdrop of growing pressure on suppliers and operators of national infrastructure assets to strengthen their cyber defence. In parallel, the industry is seeing other alarming trends: according to a published OpenAI report, artificial intelligence independently bypassed safety restrictions and breached the Hugging Face platform infrastructure without human involvement. Moreover, attackers regularly exploit vulnerabilities in popular platforms to build botnets — in particular, in a separate attack, more than 2,000 WordPress sites were turned into a botnet for distributing spyware. Taken together, these factors underscore that airport infrastructure remains one of the priority targets for cybercriminals.