Manchester Airports Group reports cyber security incident
Manchester Airports Group (MAG) has disclosed a cyber security incident involving data linked to around 8.7 million customers.
MAG, which operates Manchester Airport, London Stansted Airport and East Midlands Airport, said the incident has not disrupted airport operations. Passenger safety and aviation security were not affected.
According to MAG’s information for customers, an unauthorised third party accessed data relating to customers who used airport parking, lounges and fast-track services, as well as people who signed up for airport WiFi.
The compromised information includes email addresses, phone numbers, vehicle registration numbers and postcodes. MAG said the affected system did not hold bank or payment details.
“We immediately contained the risk and have been working with specialist advisers and taking appropriate steps to protect our customers and systems,” MAG stated.
The airport operator has informed the relevant authorities. Airport parking and other services continue to operate normally.
UK companies face growing cyber threat
The incident comes amid heightened concern about cyber attacks on British businesses, government systems and critical infrastructure.
Marks & Spencer and the Co-op suffered major attacks in 2025. M&S confirmed that some customer information was taken, but it did not include usable payment card details or account passwords. The attack caused widespread disruption, including the suspension of online orders, and M&S estimated it would reduce operating profit by around £300 million.
The Co-op also confirmed that attackers extracted personal information relating to a significant number of current and former members. Banking information, passwords and transaction details were not taken.
Following attacks on major retailers, the UK’s National Cyber Security Centre (NCSC) called the incidents a “wake-up call to all organisations.”
Department for Education targeted
In July of this year, the Department for Education disclosed a security incident involving its Customer Help Portal and Turing Scheme portal.
The department temporarily took both systems offline while it investigated and fixed the vulnerability.
Compromised information included names, job titles, email addresses, phone numbers and some business addresses. Reports initially cited around 607,000 compromised records, but the DfE clarified that the count referred to individual data lines, not 607,000 people.
Cyber attack shuts down UK power generator
Cyberattacks have also targeted Britain’s energy infrastructure. A small UK electricity generator was reportedly forced offline for four days following a cyber attack in July. The attack has been linked in reports to Iranian-affiliated hackers, although the UK government has not publicly attributed it to Iran.
The Department for Energy Security and Net Zero said the incident posed no threat to the wider electricity network.
Russia and the UK’s hybrid warfare threat
While there is no evidence that the MAG incident is connected to Russia, Ukraine or any other state actor, it comes as the UK faces warnings about Russian cyber attacks and other forms of hybrid warfare.
Russia has threatened the UK with “consequences” following reports that UK-supplied drones were used by Ukraine to strike targets inside Russia. Moscow has repeatedly accused the UK of escalating the conflict through its military support for Ukraine.

UK authorities have accused Russia of using cyber attacks, espionage, sabotage and information operations against the UK and its allies.
The NCSC and international partners warned in 2025 that Russia’s GRU military intelligence service had targeted organisations involved in transporting and coordinating assistance to Ukraine.
Targets included organisations in the defence, IT, maritime, airport, port and air traffic management sectors across NATO countries.
That does not establish any link to the MAG incident. It does, however, show why airport cybersecurity is increasingly a national security concern as well as a data protection issue.
State-backed attacks target UK infrastructure
The scale of the threat to the UK’s critical infrastructure is growing. Speaking at the RUSI Annual Security Lecture this June, NCSC chief executive Richard Horne said the agency managed more than 200 cyber incidents affecting UK critical national infrastructure and its supporting organisations between June 2025 and May 2026.
Around 75% were believed to be linked to state actors.
“In cyberspace, we are not preparing for tomorrow’s conflicts,” Horne said. “To some degree we are fighting them today.”
For MAG, the immediate impact is limited. Flights and airport operations have continued as usual. Nevertheless, the incident puts a major UK transport operator on the growing list of organisations facing cyberattacks, ranging from criminal data theft to state-backed attempts to disrupt critical infrastructure.
Sign up for our newsletter and get our latest content in your inbox.
Similar Reads
Sign up for our newsletter. Select all sectors relevant to you.
Related















