Eight Point Seven Million Airport Customers Lost Data, and the Field That Matters Is the Number Plate
Manchester, Stansted and East Midlands lost email addresses, phone numbers, postcodes and vehicle registrations taken from car park, lounge and wifi bookings. No payment details. The combination is still enough to build a message you would believe.
Sunday, August 30, 2026/4 min read

Manchester Airports Group has confirmed that an unauthorised third party obtained data belonging to around 8.7 million customers across Manchester, London Stansted and East Midlands airports.
No bank or payment card details were taken. The company says passenger safety and aviation security were never compromised, there was no operational disruption, and customers do not need to take any action beyond remaining alert to unsolicited emails and texts.
That last instruction is the one worth reading twice, because of what was taken.
What was actually in the file
Email addresses, phone numbers, postcodes and vehicle registration numbers, drawn from car parking bookings, lounge bookings, Fast Track purchases and in airport wifi sign ups at the three airports.
Read as a list, it looks like the mild end of a breach. Read as a record, it is a set of facts about one person that fit together: this address, this car, this phone, at this airport, on the day they booked.
The number plate is the part that changes the character of it. A registration is a durable identifier that most people never think of as sensitive, that appears in parking enforcement, insurance, congestion charging and private car park letters, and that almost nobody expects a stranger to know. A message quoting your plate reads as official in a way that a message quoting your email address does not.
The scam this enables, described plainly
An unpaid parking charge at the airport you actually used, for the car you actually drive, sent to the phone number you actually gave them.
Every element of that message is true except the charge. It arrives days after a real trip, it names a real airport, it quotes a real plate, and it asks for a small payment through a link. It does not need to be sophisticated because it does not need to be. The verification a person would normally do has already been done for them by the accuracy of the details.
This is why the standard advice to watch for unsolicited messages is weaker than it sounds. The advice assumes the recipient can tell a fake from a real one by looking, and the whole point of a breach like this is that the fake now contains real facts.
What to actually do
Three things, and none of them are urgent in the way a card breach is urgent.
Treat any message about airport parking, lounge access or a missed payment as false until you have checked it yourself, and check it by going to the airport or operator's own site directly rather than through any link or number in the message. If a charge is genuine, it will still be there when you get to it.
Second, if you use the same phone number and email for booking as for banking, be aware that a caller who already knows where you parked has an easier time sounding like your bank's fraud team. Banks do not ask you to move money to a safe account. Nobody legitimate ever will.
Third, do not bother changing your number plate or your postcode, because you cannot, and that is the durable lesson here. Passwords rotate. Physical identifiers do not. A company holding a registration plate is holding something it can never help you replace, which is an argument for collecting less of it in the first place.
The pattern this fits
Airports are attractive targets for a reason that has nothing to do with aviation.
An airport operator runs a retail business, a car park business, a hospitality business and a wifi network, and each of those collects customer records under a brand that people trust because it is attached to a regulated environment. The security posture that protects a runway is not the same posture that protects a lounge booking database, and the second one holds the data.
The cost side of this has been measured repeatedly, and it lands on customers as much as companies. We covered the regional numbers in the annual breach cost study, and looked at how quickly an automated attacker now moves through an exposed system in the lessons from an agent driven attack. The direction of both is the same: detection times have not improved as fast as the tooling on the other side.
The thing MAG got right
It said what was taken.
An itemised list of the fields obtained, published within days, is more useful to a customer than any reassurance, because it lets a person judge their own exposure rather than wait to be told they are fine. A company that names the categories is a company you can plan around. The ones that say only that a limited amount of information may have been accessed are the ones to worry about.
Published in The Outspoken Digest
Editorial desk
Outspoken Digest Travel DeskDestinations, airlines, borders and the practicalities of getting there.
Newsletter
The Digest, in your inbox
One edition, sent when it is ready. No noise, and your address is never passed on.
Read Next
More Travel →
A Glacier Fell 1,200 Metres Onto a River, and a Valley Full of Travellers Was Gone in Half an Hour
Aug 28, 2026/4 min read

The World's Tourists Went Somewhere Else This Year, and the Gulf Is Counting the Difference
Aug 26, 2026/3 min read

Gulf Aviation Is Heading for a $4.3 Billion Loss, and the Airspace Advisory Still Runs to 31 August
Aug 22, 2026/4 min read

One Visa, One Fee, Six Countries: the Gulf's Schengen Moment Is Reportedly Piloting This Year
Aug 21, 2026/3 min read