Reformed IT
01158 244 824Request a callback
Cyber security · 3 min read

The Breach Hitting 3 UK Airports: Why "Could've Been Worse" Is the Wrong Takeaway

8.7 million customers had their data exposed and no card details were taken. That's being treated as good news. It shouldn't be.

By Felicity Price · Aug 2026
The Breach Hitting 3 UK Airports: Why "Could've Been Worse" Is the Wrong Takeaway — Reformed ITReformed IT · Nottingham office

On 27 August 2026, Manchester Airports Group confirmed that an unauthorised third party had accessed customer data across Manchester, London Stansted, and East Midlands airports. 8.7 million customers were affected. The response online has mostly settled on “could’ve been worse.” That’s the wrong takeaway.

What happened

MAG operates car park, lounge, and Fast Track bookings, plus in-airport WiFi sign-up, across all three airports. Data tied to those services was accessed by an outside party. The group says it acted quickly to contain the incident, brought in specialist advisers, and notified the relevant authorities, according to its own statement and reporting from The Register.

The data accessed included email addresses, phone numbers, vehicle registration numbers, and postcodes. No bank or payment details were held on the affected system, so none were taken. Most of the 8.7 million people affected only had their email address exposed.

Why “no card details” isn’t the reassurance it sounds like

That’s the detail every headline led with, and it’s true. It’s also not really the point. Emptying a bank account needs card details. Writing a convincing scam doesn’t.

Name, email, and postcode is exactly what a scammer needs to send a message that looks real. Not from a random account, from “Manchester Airport,” with a real booking reference attached to prove it’s genuine. The breach itself isn’t where the damage happens. It’s what comes next: a wave of phishing emails that are harder to spot than usual, because they’re built on real information, sent to real customers, weeks after the story has stopped trending.

What we don’t know yet

As of publishing, neither MAG nor the outlets covering this have said how the attacker actually got in. That’s normal this early into an incident, the technical detail usually surfaces weeks later, if it surfaces at all. Worth remembering the next time a breach headline arrives with a confident explanation attached on day one: often nobody actually knows yet.

What this means for your business

The lesson isn’t really about airports. It’s that a breach doesn’t need to touch a bank account to cause real damage, and “no card details taken” is not the same as “customers are safe.”

If your business collects customer data anywhere (a booking form, a WiFi sign-up, a loyalty scheme) it’s worth asking two questions: do you know exactly what you’re storing, and would you know within hours if it was accessed? Most businesses can’t answer either with confidence.

If you want a clear picture of where your business stands, get in touch — it’s exactly the kind of conversation we have every day.

Felicity Price
Written by
Felicity Price
Marketing Coordinator, Reformed IT
See the team
Keep reading

Related from the team.

Related questions

Have a question this didn't answer?