MAG Breach Exposes Travel Data for Millions

Manchester Airports Group said an unauthorized party accessed customer data tied to Manchester, Stansted, and East Midlands airports, with UK reporting putting the exposure at about 8.7 million customers. The stolen records cover car park, lounge, Fast Track, and Wi‑Fi signups, along with email addresses, phone numbers, vehicle registrations, and postcodes. That mix matters because it gives attackers a believable travel context for phishing and phone scams: a message that cites a real airport booking, car details, or postcode is much easier to trust than a random spoof. MAG said bank and payment details were not taken, but it has switched off the Manage My Booking portal, showing the incident also disrupts customer self-service. For organizations that store trip-linked contact and vehicle data, the lasting risk is not only privacy harm but impersonation at scale. If a breach leaves enough booking context to sound official, the exposure can keep working long after the systems are contained.

Part of the PlainSec briefing for 2026-08-28

Editions

Sources