Manchester Airports Group (MAG) — the company that runs Manchester, London Stansted and East Midlands airports — has confirmed it was hit by a cyber security incident in which an unauthorised third party accessed a quantity of customer data. If you have booked airport parking, a lounge or Fast Track, or signed up for airport WiFi, this one may affect you.
First, the reassurance: MAG says the systems involved did not hold any bank or payment card details, and that airport operations, passenger safety and aviation security were never compromised. The data that was taken, however, still matters — it includes customers’ email addresses, phone numbers, vehicle registrations and postcodes.
Why that data makes you a target
Losing an email address and phone number can sound minor next to card details, but in the wrong hands it is the raw material for convincing scams. Armed with your email, mobile number, vehicle registration and postcode — plus the knowledge that you have used the airport — criminals can craft highly believable messages: a fake “parking refund”, a “problem with your booking”, or an “outstanding charge” that looks exactly as though it came from the airport.
That is why the single most important thing every affected customer can do now is to treat unexpected messages with suspicion. MAG has been clear that it will never contact you out of the blue to ask for payment card details, banking information or passwords — so any message that does is a scam.
How to stay vigilant
Whether or not you have been contacted directly, follow this simple guidance:
- Be wary of unexpected emails, texts or phone calls mentioning the airport, a booking or a refund.
- Do not click links or open attachments in messages you were not expecting — instead, reach the airport by typing its official web address yourself.
- Never share passwords, card or bank details in response to an inbound message.
- If a message creates urgency or pressure (“act now or lose your booking”), slow down — that is a classic scam tactic.
- For genuine booking changes, use the airport’s official customer services line, not a number supplied in a suspicious message.
The National Cyber Security Centre (NCSC) also publishes clear, free guidance for individuals affected by a data breach, and MAG’s own official statement is the place to check for updates.
No organisation is too big to be breached
Here is the part that should give every business and individual pause. Manchester Airports Group is a major, well-resourced organisation with sophisticated, high-tech systems — and it was still breached. It is far from alone. Over the past couple of years we have watched household-name retailers, airlines, banks and public bodies all fall victim to attackers who are better funded, more organised and more persistent than ever before.
The uncomfortable truth is that size, budget and technology are no longer a shield. If anything, the biggest names are the biggest targets, precisely because of the data and money involved — and when a large organisation is breached, the ripple effect reaches ordinary customers, whose details are then used to target them directly.
The lesson for all of us — global brands, local businesses and individuals alike — is the same: assume you are a target, and make awareness your first line of defence. The overwhelming majority of successful attacks still begin with a person clicking something they should not, so an alert, informed team (and household) is worth more than any single piece of technology.
How Foresight can help
For businesses, this is exactly where we focus. Foresight helps organisations across Greater Manchester and the UK build genuine cyber resilience — staff awareness training to spot phishing, multi-factor authentication, 24/7 monitoring, vulnerability scanning and Cyber Essentials certification. We are Cyber Essentials Plus certified ourselves, and we would far rather help you prepare than help you recover.
If you think you may have been affected by the Manchester Airport incident, read MAG’s official statement and the NCSC’s breach guidance — and, above all, stay alert. When in doubt, don’t click.
Source: Manchester Airports Group data security incident statement. This article is for general awareness and reflects MAG’s public disclosure at the time of writing.