If You Ever Used Wi-Fi at Manchester, Stansted or East Midlands Airport, Here’s What the 8.7 Million Breach Means for You
Hackers took 8.7 million customer records from Manchester Airports Group. Most only lost an email address, but phishing is the real risk. Here is what to do.

At a glance
- Published
- TopicMoney & Insurance
- Verified againstManchester Airports Group
- Treks coveredEverest Base Camp Trek — 12 Days
If you ever signed up for free Wi-Fi, or booked parking, a lounge or Fast Track at Manchester, Stansted or East Midlands airport, your email address may be in the stolen data. Manchester Airports Group (MAG) says about 8.7 million customers were affected, and that no bank or payment card details were held on the system the hackers reached. The practical risk is not your bank account. It is a convincing fake email or text sent to you. This applies to Britons, and also to the many Americans and Australians who fly through Stansted and Manchester on the way to Europe or Asia.

Key facts
- About 8.7 million customers affected, per MAG
- Hackers got in over the weekend of 22-23 August 2026; MAG confirmed it on 27 August
- Data taken: email addresses, phone numbers, vehicle registrations and postcodes
- MAG says no bank or payment details were stored on the system
- MAG did not pay the ransom demand
Who is actually affected, and how badly
Most of the 8.7 million lost only an email address, collected when they joined the airports’ public Wi-Fi. A smaller group, who started but did not finish a car-park or Fast Track booking, lost more. The smallest group, people with completed bookings, are the ones whose phone number, vehicle registration or postcode may also be exposed. MAG operates Manchester, Stansted and East Midlands. It does not run Heathrow or Gatwick, so a trip through those is not covered.

| What you did | Likely exposed |
|---|---|
| Joined airport Wi-Fi only | Email address |
| Started a parking or Fast Track booking | Email plus some booking details |
| Completed a parking, lounge or Fast Track booking | Email, phone, vehicle registration, postcode |
| Any of the above | No bank or card details, per MAG |
The real danger is a fake message that knows your trip
An attacker holding your email and, for some people, your registration plate and postcode can write a believable message: a parking refund, a failed Fast Track payment, a lounge survey. MAG has told customers not to click links or open attachments in unexpected emails, texts or calls, and it temporarily switched off its Manage My Booking service as a precaution. The ICO, the UK data regulator, has confirmed it received MAG’s breach report and is assessing it, and its general advice is to use a strong password and never reuse one across accounts.

What to do today, in order
Treat any message mentioning an airport, parking or a refund as suspect and go to the airport’s own website instead of tapping a link. Then check the steps below.

What this means for you
Change the password on your email account first, because it is the key to every other account, and turn on two-step verification. Forward suspicious texts free to 7726, report scam emails to Action Fraud, and ignore any message that asks you to confirm card details for an airport booking. If you paid for parking by card, your bank has not been touched by this breach, so you do not need a new card.
| Type | Where |
|---|---|
| Suspicious text | Forward to 7726 (free) |
| Scam email or fraud | Action Fraud |
| Concern about how MAG handled your data | ICO helpline 0303 123 1113 or ico.org.uk/concerns |
A legal claim is being organised, but it is early
Thompsons Solicitors has invited Scottish passengers who used the three airports to join a class action. Reporting on the action says total compensation across the UK could reach up to £100 million and individual payouts could be in the hundreds of pounds, but no deadline has been published and nothing has been awarded. Treat those figures as a claimant lawyer’s estimate, not a ruling. You do not need to do anything to protect yourself legally except keep the breach email MAG sent you.

Why this matters before a big trip
Travellers are the best phishing targets there are. They expect bookings, delays and refunds, they are often tired, and they read email on a phone. If you are heading from Manchester or Stansted to a long trek, the same habit applies to your flight, hotel and trek bookings: only pay through a website you typed in yourself or a link you started from. Our own trekkers confirm everything by WhatsApp or from our site, and never ask for card details by email.
Questions people ask
Was my payment card stolen?
MAG says neither it nor the affected system holds customer bank or payment details, so there is no sign of that in this breach.
Did Heathrow have this breach?
No. MAG runs Manchester, Stansted and East Midlands only.
Should I join the legal claim?
It is your call. Nothing is guaranteed, no deadline has been published, and the sums quoted are estimates.
Planning a trip beyond the airport? Ask us about Nepal and we will answer from Pokhara by WhatsApp.
Cover photo: Richard Cooke via Wikimedia Commons (CC BY-SA 2.0). Section photos: K via Pexels (Pexels licence); Stefan Coders via Pexels (Pexels licence); https://kaboompics.com/ via Pexels (Pexels licence); Pixabay via Pexels (Pexels licence); Sora Shimazaki via Pexels (Pexels licence).
Still running this season
Everest Base Camp Trek — 12 Days is running normally
NMA-certified local guides, transparent pricing, 5,000+ treks since 1998. Message us your dates and we'll sort the permits, lodges and logistics — reply within 24 hours, no obligation.
Popular Nepal treks
All treks →



































