Skip to content
Skip to content

Independent e-magazine

the OUTSPOKEN digest

Eight Point Seven Million Airport Customers Lost Data, and the Field That Matters Is the Number Plate

Manchester, Stansted and East Midlands lost email addresses, phone numbers, postcodes and vehicle registrations taken from car park, lounge and wifi bookings. No payment details. The combination is still enough to build a message you would believe.

Outspoken Digest Travel Desk

Sunday, August 30, 2026/4 min read

The landside concourse at Manchester Airport Terminal 2, with shops, an information desk and passengers walking through
Photo: Bob Harvey via Geograph and Wikimedia Commons (CC BY-SA 2.0)

Manchester Airports Group has confirmed that an unauthorised third party obtained data belonging to around 8.7 million customers across Manchester, London Stansted and East Midlands airports.

No bank or payment card details were taken. The company says passenger safety and aviation security were never compromised, there was no operational disruption, and customers do not need to take any action beyond remaining alert to unsolicited emails and texts.

That last instruction is the one worth reading twice, because of what was taken.

What was actually in the file

Email addresses, phone numbers, postcodes and vehicle registration numbers, drawn from car parking bookings, lounge bookings, Fast Track purchases and in airport wifi sign ups at the three airports.

Read as a list, it looks like the mild end of a breach. Read as a record, it is a set of facts about one person that fit together: this address, this car, this phone, at this airport, on the day they booked.

The number plate is the part that changes the character of it. A registration is a durable identifier that most people never think of as sensitive, that appears in parking enforcement, insurance, congestion charging and private car park letters, and that almost nobody expects a stranger to know. A message quoting your plate reads as official in a way that a message quoting your email address does not.

The scam this enables, described plainly

An unpaid parking charge at the airport you actually used, for the car you actually drive, sent to the phone number you actually gave them.

Every element of that message is true except the charge. It arrives days after a real trip, it names a real airport, it quotes a real plate, and it asks for a small payment through a link. It does not need to be sophisticated because it does not need to be. The verification a person would normally do has already been done for them by the accuracy of the details.

This is why the standard advice to watch for unsolicited messages is weaker than it sounds. The advice assumes the recipient can tell a fake from a real one by looking, and the whole point of a breach like this is that the fake now contains real facts.

What to actually do

Three things, and none of them are urgent in the way a card breach is urgent.

Treat any message about airport parking, lounge access or a missed payment as false until you have checked it yourself, and check it by going to the airport or operator's own site directly rather than through any link or number in the message. If a charge is genuine, it will still be there when you get to it.

Second, if you use the same phone number and email for booking as for banking, be aware that a caller who already knows where you parked has an easier time sounding like your bank's fraud team. Banks do not ask you to move money to a safe account. Nobody legitimate ever will.

Third, do not bother changing your number plate or your postcode, because you cannot, and that is the durable lesson here. Passwords rotate. Physical identifiers do not. A company holding a registration plate is holding something it can never help you replace, which is an argument for collecting less of it in the first place.

The pattern this fits

Airports are attractive targets for a reason that has nothing to do with aviation.

An airport operator runs a retail business, a car park business, a hospitality business and a wifi network, and each of those collects customer records under a brand that people trust because it is attached to a regulated environment. The security posture that protects a runway is not the same posture that protects a lounge booking database, and the second one holds the data.

The cost side of this has been measured repeatedly, and it lands on customers as much as companies. We covered the regional numbers in the annual breach cost study, and looked at how quickly an automated attacker now moves through an exposed system in the lessons from an agent driven attack. The direction of both is the same: detection times have not improved as fast as the tooling on the other side.

The thing MAG got right

It said what was taken.

An itemised list of the fields obtained, published within days, is more useful to a customer than any reassurance, because it lets a person judge their own exposure rather than wait to be told they are fine. A company that names the categories is a company you can plan around. The ones that say only that a limited amount of information may have been accessed are the ones to worry about.

Published in The Outspoken Digest

Editorial desk

Outspoken Digest Travel Desk

Destinations, airlines, borders and the practicalities of getting there.

Newsletter

The Digest, in your inbox

One edition, sent when it is ready. No noise, and your address is never passed on.

We send a confirmation first. One click to leave, always.

Share this story

the OUTSPOKEN digest

Beyond boundaries. Independent stories on technology, culture, and the trends shaping how we live.