Skip to content
Cyber Security Firms

Manchester Airports Group Data Breach (August 2026)

Manchester Airports Group disclosed a cyber security incident on August 27, 2026 involving car park, lounge, Fast Track and airport WiFi records at Manchester, Stansted and East Midlands, and Have I Been Pwned verified 8,849,657 email addresses after the FulcrumSec group published the data.

Disclosed Updated
Organization
Manchester Airports Group
Country
United Kingdom
Incident date
August 27, 2026
Disclosed
August 27, 2026
Records affected
8.8 million
Attack type
Undisclosed
Threat actor
FulcrumSec
Status
Confirmed
Data exposed
  • Browser user agent details
  • Email addresses
  • Geographic locations
  • IP addresses
  • Names
  • Phone numbers
  • Purchases
  • Vehicle registration plates
Timeline
  1. Manchester Airports Group publishes its data security incident statement, the date Have I Been Pwned also records as the breach date
  2. SecurityWeek reports the FulcrumSec extortion group claiming the attack and about 86 GB of stolen data
  3. Have I Been Pwned loads 8,849,657 verified email addresses from the published data
  4. SecurityWeek reports roughly 550 GB of uncompressed data published, with the group saying no ransom was paid

What Happened

Manchester Airports Group runs Manchester, London Stansted and East Midlands airports. On August 27, 2026 the group published a data security incident statement saying it had been subject to a cyber security incident by an unauthorized third party, and that customer data relating to car park, lounge and Fast Track bookings and in-airport WiFi sign-ups at the three airports had been obtained. In the company's own notice MAG says it contained the risk immediately, is working with specialist advisors and has informed the relevant authorities, and that "at no point has passenger safety or aviation security been compromised."

The FulcrumSec extortion group claimed responsibility over the following weekend, saying it had taken about 86 gigabytes of data, as reported by SecurityWeek on August 31. MAG has since confirmed that the stolen information sat in a database hosted by a third party and that it received a ransom demand, and the group has published roughly 550 gigabytes of uncompressed data and stated that MAG did not pay, according to SecurityWeek's September 3 report.

On September 2, Have I Been Pwned parsed that published data and loaded 8,849,657 verified email addresses from it. That verification, rather than the group's claim, is why this report is filed as confirmed and where the record count on the fact grid comes from.

FulcrumSec told SecurityWeek it got in using admin keys left in plain sight "in the frontend JavaScript of each of its three airports' websites." MAG has not confirmed that route, and SecurityWeek says it has not independently verified the group's claims, so the attack type here stays Undisclosed. Have I Been Pwned records the breach date as August 27, 2026, the same day MAG published its statement; MAG has not said when the access began.

What Was Exposed

Per the Have I Been Pwned entry, the verified data holds email addresses, names, phone numbers, geographic locations, IP addresses, browser user agent details, purchases and vehicle registration plates. MAG describes the same set in its notice as email addresses, phone numbers, vehicle registrations and postcodes, and says that "Neither MAG nor the system accessed hold customers' bank or payment details."

No single field there is dangerous on its own. The combination is: a name, an email address, a phone number, a home postcode, a car's plate and the record of a specific parking, lounge or Fast Track booking at a named airport. SecurityWeek reports FulcrumSec claiming the set covers 2,482,763 purchases, 461,433 SMS messages tied to bookings and 108,077 unique UK vehicle registration plates, and notes those figures are the group's own and unverified. A scam message written from that data does not have to guess anything, which is what separates it from ordinary spam.

What to Do If You Are Affected

No passwords and no card numbers appear in the data classes, so there is no password to rotate here and no card for a bank to replace. The rest of the order of operations, including when a credit freeze earns its place, is in what to do after a data breach, and the shape these follow-on messages take is set out in how a phishing message is built. The other travel and transport breaches on record here show how often booking data is the part that leaks.

What Is Not Known Yet

When the intrusion began and how long it lasted. MAG has not said, and the August 27 date on the fact grid is the breach date Have I Been Pwned records, which is the day the statement went out. Which third-party hosted database held the records and whether the supplier is named. Whether MAG's own account of the entry point matches FulcrumSec's claim about exposed keys. And which authorities MAG has informed, since the notice says it has informed them without naming them. This report is updated as the record grows.

Sources

  1. Manchester Airports Group, Data Security Incident statement and FAQs
  2. Have I Been Pwned: Manchester Airports Group
  3. SecurityWeek, Extortion Group Claims Manchester Airports Group Data Breach, August 31, 2026
  4. SecurityWeek, Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal, September 3, 2026
On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →