Security Guides
What leaked is when your car sits at the airport — the Manchester Airports Group (MAG) data breach and fake parking refund or booking-problem messages
On August 27, 2026, Manchester Airports Group (MAG) said an unauthorised third party obtained customer data linked to parking, lounge and Fast Track bookings and Wi-Fi sign-ups at Manchester, Stansted and East Midlands airports: emails, phone numbers, vehicle registrations and postcodes. What travellers should do.
For: anyone who has booked parking, a lounge or Fast Track security at Manchester, London Stansted or East Midlands airports, or signed up to the in-airport Wi-Fi, including visitors from abroad. This article is based on Manchester Airports Group (MAG)'s official statement and FAQ, and guidance from the UK's National Cyber Security Centre (NCSC) and Information Commissioner's Office (ICO), and does not cover attack techniques.
What to do today
Treat any message about the airport, your booking or your car with suspicion
MAG urges customers to be vigilant for suspicious emails, texts and calls and not to click links or open attachments in unexpected communications. The NCSC likewise warns that after a breach you may see official-sounding messages about "receiving compensation" or "resetting passwords", and messages urging you to act immediately. A correct date or number plate does not prove a message is genuine (basics: What is phishing?).
Handle refunds, changes and cancellations yourself in Manage Booking
According to MAG, all upcoming bookings remain valid and you do not need to take any action. If you want to change dates or cancel because of the incident, you can do so at no charge, and cancellations due to the incident will be fully refunded. Do it through Manage Booking on the airport's official website, reached by typing the address yourself. "Enter your card details at this link to receive your refund" appears nowhere in that process.
Never give card numbers, bank details or passwords to anyone who asks
MAG says it will never contact you unexpectedly to request payment card details, banking information or passwords. If a caller "verifies" you by correctly quoting your number plate or postcode, that may simply be leaked data. Hang up and call back on the number on the official website.
Don't pay a 'parking fine' text; check it independently
UK councils have warned about texts impersonating parking Penalty Charge Notices (PCNs). Wandsworth Council in London, for example, says "We will never send a text message asking you to pay a PCN." Even if the text shows your correct registration, don't pay through its link.
If you've lost money, call your bank and report to Report Fraud
The NCSC says that if you have lost money, tell your bank and report it to Report Fraud, the UK's reporting centre for fraud and cyber crime (in Scotland, call the police on 101). Report Fraud replaced Action Fraud in December 2025; the phone number (0300 123 2040) is unchanged. For a card issued abroad, call the number on the back of your card.
Forward suspicious messages
The NCSC asks you to forward suspicious emails to report@phishing.gov.uk and suspicious texts to 7726 (free). The ICO also suggests watching bank statements, checking your credit report, and using strong passwords and multi-factor authentication.
Parking, lounge, Fast Track booking
+ email address, phone number
↓→
"A problem with your booking, we'll refund you"
→ Don't follow links; open official Manage Booking
Vehicle registration
+ phone number
↓→
"Unpaid parking fine for your vehicle"
→ Never pay by text link; check with the issuer
Postcode
(reveals your area)
↓→
A caller who "verifies" you with your postcode
→ Knowing it ≠ genuine. Hang up, call back
Not held (per MAG): bank and payment card details
What happened (from MAG's statement)
Everything below is as stated in MAG's statement and FAQ ("Data Security Incident - 27.08.26") on the three airports' official websites. The three pages are identical apart from pointing to each airport's own Manage Booking page.
August 2026
MAG is subject to a cyber security incident by an unauthorised third party. Customer data relating to parking, lounge and Fast Track bookings and in-airport Wi-Fi sign-ups at the three airports is obtained.On becoming aware
MAG says it immediately contained the incident by restricting access to the affected system, engaged specialist cyber security experts and notified the relevant authorities, with its Data Protection team overseeing the response. According to press reports, MAG became aware on Tuesday, August 25.August 27, 2026
MAG publishes its statement (the date in the page heading).Since then
MAG says all affected customers have been informed and that it continues to work with the relevant authorities.
- Services involved
- Car park, lounge and Fast Track bookings and in-airport Wi-Fi sign-ups at the three airports
- Data involved
- Email addresses, phone numbers, vehicle registrations and postcodes
- Not involved
- Neither MAG nor the system accessed holds customers' bank or payment details
- Publication
- For people notified that they were affected, MAG says their data was made publicly available
- Bookings
- All upcoming bookings remain valid. Changes and cancellations because of the incident are free, and such cancellations are fully refunded
- Airport operations
- Operational airport systems were not involved; no impact on operations; passenger safety and aviation security were never compromised
- Response
- Restricted access to the affected system, engaged specialists, notified the relevant authorities, contacted affected customers directly
Reading note: the number and the cause are not in the official statement
The 8.7 million figure is not in MAG's statement; it is what a MAG spokesperson reportedly told a UK newspaper. The cause, the method of entry and which system was involved have not been published. Some reports mention a demand for money; this article covers only MAG's statement and figures that can be traced to a source.
A parking booking is both a scam script and a note of when you're away
Leaks of email addresses and phone numbers are common. What makes this one different is that airport bookings and number plates come with them.
What a contact-only list lets a scammer write
- "There is a problem with your account"
- "We couldn't deliver your parcel"
- Easy to ignore, because it rings no bells
What a list with bookings and plates lets a scammer write
- "There is a problem with your airport parking booking; we'll refund you"
- "Your vehicle (plate ...) has an unpaid parking fine"
- The people who really booked feel "this is about me"
First, refund and booking-problem scams become more convincing. The NCSC warns about scammers pretending to be the organisation that suffered a breach and about "compensation" messages. Whether this data has been used in scams has not been published, but a message that names the right airport and your real plate is far harder to doubt.
Second, a point this site wants to add. An airport parking booking is also a record of when you are away from home and which car is sitting at the airport, and a postcode narrows down where you live. That knowledge can lend weight to calls like "about your home while you're travelling" or "on behalf of your partner who is abroad", or to messages sent to family while you are away. The countermeasure is simple: never treat knowledge of your plans or your plate as proof of identity or trustworthiness. Tell your family too: "even if they know I'm travelling, don't hand over money or information until you've checked with me directly."
This site's view: learn the one genuine refund route, and you never need to judge the fake
Tips for spotting fake texts (misspelled URLs, odd wording) stop working as scammers get better. More reliable is knowing the genuine route in advance. With MAG, bookings stay valid and changes or cancellations are made by you, in the official Manage Booking page you open yourself. "Open the link and enter your card number to get a refund" doesn't fit that route, so you can call it fake without reading any further.
It is easy to miss that Wi-Fi sign-ups are included. If you "entered your email to connect" at the airport, your contact details may be included even if you never booked anything. When signing up to Wi-Fi in public places, a separate email address you don't use for important accounts limits the damage if it leaks (The dangers of public Wi-Fi).
We covered fake messages built on travel bookings in the case of a hotel booking platform (the Booking.com data breach) and Italy's railway (the Trenitalia data breach). A breach from the same period, where an internal reporting tool exposed student and parent data, is covered in the Mathspace data breach.
Sources (public record)
The facts in this article come from the public sources below. We do not repeat speculation from press coverage, or causes and amounts that cannot be confirmed officially.
- Manchester Airport, "Data Security Incident - 27.08.26" (MAG statement and FAQ) — manchesterairport.co.uk
- London Stansted Airport, same page — stanstedairport.com
- East Midlands Airport, same page — eastmidlandsairport.com
- The Record, report of August 27, 2026 (reports that a MAG spokesperson told a UK newspaper roughly 8.7 million people were affected) — therecord.media
- NCSC, "Data breaches: guidance for individuals and families" — ncsc.gov.uk
- NCSC, "Report a scam email" — ncsc.gov.uk
- ICO, "What steps can I take if I've been affected by a personal data breach?" — ico.org.uk
- GOV.UK, "Report Fraud: new service from City of London Police" (December 4, 2025) — gov.uk
- Wandsworth Council, "Parking scam text message warning for residents" (June 24, 2026) — wandsworth.gov.uk
Update history
2026-09-30: First version, based on MAG's statement and FAQ on the three airports' official websites and NCSC and ICO guidance for individuals. The number affected is as reportedly given by a MAG spokesperson. The technical cause, the timing of the intrusion and the system involved have not been published; we will update this page if they are.
Read next
- Fake messages built on travel bookings: The Booking.com data breach / The Trenitalia data breach (Italy)
- Spotting fake messages: What is phishing?
- Airport and hotel Wi-Fi: The dangers of public Wi-Fi
- A breach from the same period: The Mathspace data breach (Australia and New Zealand)
- Other 2026 incidents: Data breaches and cyberattacks of 2026
FAQ
QWhat was exposed in the Manchester Airports Group (MAG) data breach?
According to MAG's statement, customer data relating to car park, lounge and Fast Track bookings and in-airport Wi-Fi sign-ups at Manchester, London Stansted and East Midlands airports was obtained by an unauthorised third party. The data listed is email addresses, phone numbers, vehicle registrations and postcodes.
QWere card or bank details exposed?
MAG says neither it nor the system accessed holds customers' bank or payment details. It also says it will never contact you unexpectedly to request payment card details, banking information or passwords.
QHow many people were affected?
MAG's official statement does not give a number. According to press reports, a MAG spokesperson told a UK newspaper that roughly 8.7 million people were affected (no date range was given). MAG says all affected customers have been informed.
QWas the data published online?
In its FAQ, MAG says that if you have been notified that you were affected by the incident, your data was made publicly available. If you received that notice, it is safest to assume that your email address, phone number, vehicle registration and postcode can be known to others.
QIs my booking still valid? Can I cancel?
According to MAG, all upcoming bookings remain valid and are unaffected, and you do not need to take any action regarding your booking. If you want to change the dates or cancel because of the incident, you can do so at no charge, and cancellations due to the incident will be fully refunded. Use Manage Booking on the airport's official website.
QI'm a visitor from abroad who booked a lounge or Fast Track. Am I affected?
MAG's statement covers data relating to parking, lounge and Fast Track bookings and Wi-Fi sign-ups at the three airports, and does not distinguish by nationality. MAG says it contacted affected customers directly. Even without a notice, it is safest to expect airport- or booking-themed messages to the email address or phone number you used.
QWhat caused it? Were flights affected?
MAG describes a cyber security incident by an unauthorised third party but has not published a technical cause. It says the incident did not involve operational airport systems, had no impact on airport operations, and that at no point was passenger safety or aviation security compromised.