Business

8.7 million records taken from three airports. Most of it came from the free WiFi.

Manchester Airports Group says attackers took email addresses, postcodes and vehicle registrations belonging to about 8.7 million customers, then demanded a ransom. MAG refused to pay. No card data was involved — because the breached systems were never the ones anyone called critical.

N Noah · The Sharp Brief · August 29, 2026 · 4 min read
An empty airport terminal at night with blank display screens

Nobody puts the terminal WiFi portal on the risk register.

Manchester Airports Group — which runs Manchester, London Stansted and East Midlands — disclosed this week that criminals accessed customer data belonging to roughly 8.7 million people. The stolen fields are email addresses, postcodes and vehicle registration numbers. MAG says the attackers demanded a ransom and that it refused to pay.

The group identified the incident on Tuesday, says it contained it, brought in specialist advisers and began notifying affected customers. It has told the BBC it knows who the attackers are, while declining to name the group publicly or disclose the sum demanded. The UK’s Information Commissioner’s Office has confirmed it received a breach notification and is assessing it.

The systems that don’t feel like systems

The detail that makes this worth a business reader’s attention is where the data lived. Most of the exposed records came from passengers signing up for WiFi in the terminals. The rest came in through car-park reservations, lounge bookings and fast-track security purchases.

None of those is an operational system. MAG has been explicit that passenger safety, airport operations and aviation security were unaffected, and that the compromised environment held no bank account or payment-card data. Every one of those statements is true and none of them makes the problem smaller.

The WiFi portal is a marketing asset. It exists to trade internet access for an email address. Over years and tens of millions of passengers, that trade quietly assembled one of the larger consumer datasets in British transport — held in a system that was never designed, funded or reviewed as though it held one. The parking and lounge platforms did the same thing with richer fields attached: a postcode and a licence plate are worth considerably more to a fraudster than an email alone.

Our take: The absence of card data is being reported as mitigation. It isn’t, particularly. Card fraud is bounded, insured and reversible. What was taken here is the raw material for extremely convincing phishing — a real email address, a real postcode, a real vehicle registration, all tied to a real airport the person actually used. A fake parking-charge notice quoting your own number plate is a different proposition from a generic scam text, and MAG has already warned customers to expect exactly that. The broader lesson is a boring one that most companies still get wrong: data liability accumulates wherever a form field does, not wherever the security budget goes. If your marketing stack has been collecting email addresses for a decade, your marketing stack is a target, and it is almost certainly not defended like one. The same pattern showed up in workplace monitoring apps this month.

What to watch

Advertisement

Get the day, decoded — at 7 PM ET

The Sharp Brief: AI, money, business & performance in five sharp minutes. Free.

Free bonus: subscribe today and The 2026 Side-Hustle Playbook lands with your welcome email.

Recommended by 5+ newsletters across AI, markets & business.