High

Manchester Airports Breach: 8.7M Passengers' Data Leaked (2026)

By Yazoul AI · automated

In August 2026, Manchester Airports Group (MAG) disclosed a data breach impacting their services . The incident was later claimed by the FulcrumSec hacking group , who subsequently published email addresses and phone numbers relating to 8.7M customers of Manchester, Stansted and East Midlands airpor...

Overview

On August 12, 2026, Manchester Airports Group (MAG) confirmed a data breach affecting customers of its three airports: Manchester, Stansted, and East Midlands. The attack was claimed by the FulcrumSec hacking group, which released a database containing 8,728,451 records with email addresses and phone numbers tied to airport services.

The leaked data covers passengers who booked parking, Fast Track security passes, or lounge access between 2021 and 2026. The dataset also includes vehicle registration plates and parking history details. MAG, which owns and operates all three UK airports, stated in its disclosure that “at no point has passenger safety or aviation security been compromised.”

This breach has been indexed by Have I Been Pwned, meaning affected individuals can verify exposure through that service. The full dataset is reportedly circulating on hacking forums, raising the risk of targeted phishing and vishing campaigns.

What Was Exposed

The breached records contain a mix of direct identifiers and behavioural data:

  • Email addresses: Primary login identifiers for MAG’s online booking systems
  • Phone numbers: Mobile and landline numbers linked to travel bookings
  • Vehicle registrations: Number plates captured for airport parking services
  • Parking history: Dates, durations, and transaction timestamps
  • Booking metadata: References to Fast Track purchases and lounge reservations

No passport numbers, payment card data, or government-issued identification were included in the leaked files, according to MAG’s preliminary analysis. However, the combination of personal contact details with travel patterns is valuable intelligence for social engineering attacks.

How the Breach Happened

FulcrumSec, a relatively new extortion-focused group, claimed responsibility on a dark web forum in early August 2026. The group stated it gained access through a compromised administrative account linked to a third-party parking management vendor used by MAG.

The vendor relationship appears to be the entry point. FulcrumSec claimed the vendor’s systems held cached copies of MAG customer records, which were then exfiltrated over a six-week period before detection. MAG’s public statement confirms the breach involved “a third-party supplier” but does not name the company.

MAG discovered the intrusion on July 28, 2026, after FulcrumSec posted a sample of the data as proof. The group demanded a ransom to delete the full database, but MAG declined to comment on whether any payment was made. The full dataset was published on August 15, 2026.

Phishing and Vishing Risks

The exposed contact details create a clear pathway for credential theft. Attackers can now send highly convincing emails referencing specific parking reservations or lounge bookings, since the leaked metadata provides real booking references and dates.

Voice phishing (vishing) is a particular concern here. With phone numbers and vehicle registrations, scammers can pose as MAG parking enforcement or customer service staff, claiming issues with a parking fine or a booking discrepancy. These calls could extract additional personal information, such as home addresses or payment card details.

The presence of vehicle registration plates adds a further risk. Registration numbers can be used in DVLA phishing scams or to build detailed profiles of victims’ movements, which may enable physical security threats for high-profile individuals.

How to Check If You’re Affected

You can determine whether your data was compromised in two ways:

  1. Have I Been Pwned: Visit https://haveibeenpwned.com/Breach/ManchesterAirportsGroup and enter the email address you used for MAG bookings. The service will confirm if your record appears in the leaked dataset.
  2. MAG’s notification system: Manchester Airports Group has been sending email notifications directly to affected customers. Check the inbox of the email account used for parking, Fast Track, or lounge bookings.

If you booked airport services between 2021 and 2026 and have not received a notification, you may still be affected. MAG recommends treating any unsolicited communication referencing airport bookings with suspicion, regardless of whether the breach notification arrived.

What to Do Right Now

Email security: Change the password for the email account linked to your MAG bookings immediately. If you reuse that password elsewhere - particularly for banking or government services - change those accounts too. Enable multi-factor authentication on all email accounts.

Phone awareness: Treat all unsolicited calls referencing airport services as potential scams. Hang up and call MAG directly using the number on their official website. Never provide additional personal details over an unsolicited call.

Be alert for phishing: Do not click links in emails claiming to be from MAG asking you to verify booking details. Legitimate communications will direct you to the official magairports.com domain, not third-party look-alike URLs.

Monitor for SIM swapping: With phone numbers exposed, there is a risk of SIM-swap attacks. Contact your mobile provider to add a security PIN or note to your account that blocks number transfers without in-person verification.

Vehicle security: If you received a parking fine notice or enforcement letter referencing your registration plate, verify it directly with the relevant airport authority before paying anything.

Security Insight

This breach underscores a recurring weakness in the travel sector: third-party vendors accumulating sensitive customer data without adequate access controls or encryption. MAG’s core aviation systems were untouched, but its parking partner’s weak administrative security was enough to expose millions of customer records for over a month. The disclosure that “passenger safety has not been compromised” deflects the true concern - the aviation group failed to apply the same security rigour to its peripheral vendors as it does to its primary operations. Until travel companies enforce contractual data-minimisation and mandatory encryption on all supplier systems, similar incidents will remain a predictable outcome.

Further Reading

Investigate Breaches Safely with NordVPN

Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.

Get NordVPN for Research

Affiliate link — we may earn a commission at no extra cost to you.

Share:

Never miss a data breach report

Get real-time security alerts delivered to your preferred platform.

Related Breach Reports

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.