Manchester Airports Group Breach: What It Means For You
MAG confirmed a breach affecting 8.8 million customer records from Manchester, Stansted and East Midlands airports.
Updated 2026-09-26
What happened
In August 2026, Manchester Airports Group, which runs Manchester, Stansted and East Midlands airports, disclosed a data breach. A hacking group calling itself FulcrumSec later claimed responsibility and published records relating to 8.8 million customers. The exact day the breach occurred has not been made public, only the month.
The data included email addresses, phone numbers, names, IP addresses, browser user agent details, geographic locations, purchase information and vehicle registration plates. Much of it relates to specific airport services: parking bookings and history, Fast Track purchases, and airport lounge bookings. The breach was added to Have I Been Pwned on 2 September 2026, which is where the details above are confirmed.
MAG's own disclosure states that "at no point has passenger safety or aviation security been compromised". Nothing in the available information contradicts that.
What this actually means for you
If you have used parking, Fast Track or lounge services at any of these three airports, some of your contact and booking details may be part of this. That is not the same as your accounts or your money being at risk directly. What it does mean is that someone else may now have your email address, phone number, and details about a specific trip you took, including your car's registration plate.
That combination is useful to a scammer. A message that says "there's a problem with your parking booking" or "your vehicle registration needs verifying" sounds far more convincing when it references something real. That is the practical risk here: not that your accounts have been broken into, but that someone may use these details to make a scam message look legitimate.
It is not yet known whether any specific individual, including any Veystrix customer, is definitely among the 8.8 million affected. If you've used any of these airports' paid services in the past, it is reasonable to assume you might be.
What to do
- Treat any unexpected call, text or email that references your parking, Fast Track or lounge booking with suspicion, even if it includes correct details like your vehicle registration. Scammers can use exposed data to sound convincing.
- Do not click links in unsolicited messages claiming to be from Manchester, Stansted or East Midlands airport, and do not hand over further personal or payment details in response to one.
- If a message asks you to "confirm" your card details, log in via a link, or pay an unexpected fee, that is a strong warning sign regardless of how accurate the rest of the message sounds.
- Report anything suspicious to Action Fraud.
- Passwords do not appear to be among the data types exposed in this breach, so there is no confirmed reason to change your airport account password specifically. Turning on two-factor authentication where it is offered is still sensible practice generally, breach or no breach.
If you get a message and you are not sure whether it is genuine, Veystrix's free scam checker at /tools/scam will look at the wording and flag common manipulation tactics before you act on it. If a message contains a link you are wary of, /tools/url will check where it actually leads without you having to open it.
What this does not fix
A VPN would not have prevented this breach and would not remove your details from data that has already been published. This was a breach of MAG's own systems, not something that happened to your device or your home network. Using a VPN encrypts your connection and hides your browsing from your internet provider, but it has no bearing on data a company was storing about you before the breach happened.
What you can do now is limited to reducing the damage: being sceptical of messages that reference this data, not reusing the same password across services if you're unsure, and checking whether your email address has shown up in this or other breaches using a tool like /tools/password, which checks a password against known breach data in your browser without sending it anywhere. None of this undoes the exposure. It just reduces the chance that someone else profits from it.
Check a password Free, and it needs no account.