Personal data belonging to approximately 8.7 million people has been published online following a major cyberattack targeting three of the UK's leading airports. Cybercriminals breached systems belonging to Manchester Airports Group, which operates Manchester Airport, London Stansted Airport, and East Midlands Airport, and demanded an undisclosed ransom. When that ransom went unpaid, the attackers uploaded the stolen records to their own website, making them freely accessible to third parties, including scammers. The airport operator says it has since put protection measures in place and reached out directly to both affected travellers and passengers with future bookings to offer security guidance.
Half a Terabyte of Customer Information Exposed
The compromised records reportedly include contact details, vehicle registration numbers, postcodes, and data tied to airport Wi-Fi logins and car parking reservations. An analysis by breach-tracking platform Have I Been Pwned confirmed the leaked material contains email addresses, phone numbers, residential addresses, vehicle plates, purchase records, and device-browsing data. The cybercrime group behind the attack, which hasn't been publicly named, claimed the full dataset amounts to roughly half a terabyte of purely personally identifiable information.
What makes this particular case more concerning than a typical breach is where the data ended up. Rather than confining the leaked files to the dark web, where access is at least somewhat restricted, the hackers hosted everything on the open internet, dramatically widening who can actually get hold of it, including opportunistic criminals who wouldn't normally have the technical means to access dark-web marketplaces.
Why Travel Data Specifically Raises New Concerns
Cybersecurity specialists have warned this exposure carries risks that go well beyond standard fraud or spam. Security researcher Kevin Beaumont noted that the leaked archive includes both historical location data and planned future travel details, information that could pose genuine safety risks for anyone whose physical movements need to stay confidential for personal or professional reasons.
Beaumont also cautioned that attackers could weaponise verified phone numbers, vehicle registrations, and detailed personal profiles to craft highly convincing social engineering scams, the kind of targeted phishing that's much harder to spot precisely because it's built on real, verified personal details rather than guesswork. Notably, the attackers claimed they'd compromised multiple organisations using the same underlying method, pointing to what they described as broader lapses in how companies manage and store digital network access keys, suggesting this breach may not be an isolated incident.
How Authorities and the Airport Operator Have Responded
Manchester Airports Group confirmed it's working with law enforcement and specialised cybersecurity consultants to investigate the breach, while stressing that physical safety at all three aviation hubs was never compromised at any point during the incident.
On the ransom question, the UK's National Crime Agency and other policing bodies maintain a firm stance: victims are advised against paying, on the grounds that doing so finances criminal infrastructure and encourages further extortion campaigns against other organisations down the line.
What Affected Customers Should Do
Security experts are advising anyone affected to monitor their financial records closely, enable multi-factor authentication wherever possible, use unique passwords rather than reusing them across accounts, avoid sharing credentials with unverified contacts, and immediately alert the relevant issuers if government ID cards, driving licences, or credit cards were among the compromised data.
FAQs
Q1. Which airports were affected by this cyberattack?
Manchester Airport, London Stansted Airport, and East Midlands Airport, all operated by Manchester Airports Group.
Q2. How many people had their data exposed?
Approximately 8.7 million people, with the leaked dataset amounting to roughly half a terabyte of personal information.
Q3. Why did the attackers publish the data on the open internet instead of the dark web?
Doing so significantly widens access to the stolen information, making it available even to opportunistic criminals who wouldn't normally have the technical means to access dark-web marketplaces.
Q4. What should affected travellers do to protect themselves?
Monitor financial records, enable multi-factor authentication, use unique passwords, avoid sharing credentials with unverified contacts, and immediately notify relevant issuers if ID documents or credit cards were compromised.