A cyberattack on three major UK airports has compromised the personal data of nearly nine million customers, with hackers demanding a ransom that the airport operator has refused to pay.
Manchester Airports Group (MAG), which owns Manchester, East Midlands, and London Stansted airports, confirmed that hackers accessed the email addresses, phone numbers, postcodes, and vehicle registration numbers of customers over the weekend. The group told the media it declined to pay the ransom demanded for the data’s return, without disclosing the amount sought.
MAG said passenger safety and aviation security were not compromised at any point, and that the breached system did not store the bank or payment details of customers.
Around 8.7 million customers were affected, though the majority had only their email addresses exposed, linked to WiFi sign-ups at airport terminals. More detailed information, including vehicle registrations, came from customers who had booked car parking, lounge access, or fast-track services.
The group said it became aware of the breach on Tuesday and moved quickly to contain it, working with specialist advisors and notifying affected customers and relevant authorities. It urged customers to remain alert to suspicious emails, calls, and text messages, and to avoid opening unknown attachments.
Michael Goddard, 71, from Cheshire, said he and his wife had both received breach notifications from MAG after using East Midlands and Manchester airport services this year. He described the experience as alarming, saying his stolen postcode and name could make him easy to identify, and called for assurance of compensation if the data is misused.
MAG said the identity of the hackers was known and that it had informed relevant authorities. The Information Commissioner Office said it was assessing the incident.