A cyber attack has hit three UK airports, exposing the personal information of 8.7 million customers. Over 66 million passengers travel from Manchester, London Stansted, and East Midlands airports per year.
The data breach leaked information from the car park, lounge, Fast Track bookings, and Wi-Fi services. The operator said it immediately contained the threat to stop it from spreading. No disruption of aviation services or compromise of aviation safety was recorded.
Cyber attack at UK airports leaks personal information of 8.7 million people
According to Manchester Airports Group (MAG), which operates the affected UK airports, the data breach leaked email addresses, phone numbers, postcodes, and vehicle registration numbers.
However, the cyber attack did not compromise payment details, disrupt operations at the affected UK airports, or undermine passenger or aviation safety.
MAG said it immediately contained the threat and has started notifying impacted individuals and relevant authorities. The Information Commissioner’s Office has confirmed that it was notified of the cyber attack. MAG is also working with experienced data specialists on the best way to protect customer information.
“We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems,” MAG stated.
MAG also reaffirmed its commitment to protecting the security of customer information.
“We would like to reassure customers that Manchester Airport Group takes the security of customer information extremely seriously and we apologise for any inconvenience or concern caused.”
It also advised victims to remain vigilant for unsolicited messages from individuals purporting to work with the affected UK airports, adding that it does not request payment information or passwords from passengers.
“We would urge you to be particularly cautious of unexpected emails, calls or text messages claiming to be from us,” London Stansted told its customers,” MAG said. “We will never contact you unexpectedly to ask for payment or banking information. We apologise for any inconvenience or concern this may cause.”
Meanwhile, MAG says the threat actor behind the cyber attack at the three UK airports has demanded a ransom to avoid publishing the stolen information online. Cybercrime gang FulcrumSec has publicly claimed responsibility for the cyber attack and says it stole 86 GB of compressed data containing over 200,000 records.
FulcrumSec reportedly exploited compromised credentials exposed via client-side JavaScript. However, it remains unclear whether it attempted to install ransomware.
“What’s more interesting to us from a technical standpoint is the attack path,” said Denis Calderone, CTO, Suzu Labs. “MAG told The Register that attackers compromised one of their internal systems and then went on to steal files from a database hosted by a third party. That’s a pivot upstream into a data provider, not downstream into operational systems. What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG’s network first. That distinction matters for understanding where detection controls failed and who was responsible for monitoring the egress.”
Another attack on critical infrastructure
Airports are part of critical infrastructure and have frequently come under attack by various cybercrime groups to disrupt operations and steal personal information.
In September 2025, several European airports, including the continent’s busiest, Heathrow Airport, were affected by a cyber attack targeting Collins Aerospace, a boarding and check-in software provider. Other airports affected included Berlin Airport, Dublin Airport, Brandenburg Airport, Brussels Airport, and Cork Airport.
The attack disrupted operations, causing delays, and prompting the affected airports to switch to manual systems. Some began tagging luggage by hand, slowing down the boarding process due to staff shortages.
In 2024, UK airports Heathrow, Gatwick, Manchester, and Birmingham were affected by a CrowdStrike global outage, resulting in the cancellation of 207 outbound flights and 201 inbound flights. In total, over 6,855 flights were canceled worldwide after CrowdStrike’s software updates affected flight and train services.
In the same year, the US Pacific Northwest’s busiest airport, Seattle-Tacoma International Airport, was hit by a ransomware attack that impacted maritime operations.

