UK Airports Cyber-Attack Exposes Personal Details of 8.7 Million Customers During Peak Summer Travel Chaos

Pressure is now mounting on national operators to rapidly overhaul their digital defences

UK Airport Data Breach Alert
Critical UK transport infrastructure has been dealt a heavy digital blow after a major cyber-security breach exposed the records of 8.7 million travellers across three key airport hubs Gemini

Roughly 8.7 million travellers have had their personal records compromised following a cyber strike targeting Manchester, London Stansted and East Midlands airports.

According to Manchester Airports Group, which runs all three locations, the security breach affected details tied to fast-track, lounge and car park reservations, alongside terminal Wi-Fi accounts. The attackers accessed users' phone numbers, email addresses, postcodes and vehicle registrations.

8.7 Million Customers' Data Accessed

The operator said that 'at no point has passenger safety or aviation security been compromised', adding that terminal routines continued normally. It also confirmed that payment details and financial records remained completely untouched by the breach.

Customers Warned Over Scam Messages

London Stansted reached out to customers directly via email to warn them to stay alert for unsolicited texts, phone calls or messages pretending to be from the airport. The notice stressed that the team 'will never contact you unexpectedly to ask for payment or banking information', while also sharing that 'we apologise for any inconvenience or concern this may cause.'

The security breach struck in the middle of the busiest holiday weeks, with countless families returning home ahead of the new school year. Together, the three travel hubs handled more than 54 million passengers over the course of last year.

Airport Operations Remain Unaffected

A representative for the company explained that the firm 'immediately contained the risk' following the breach and is currently 'working with specialist advisers and taking appropriate steps to protect our customers and systems.'

The spokesperson added that 'we have informed and are working with the relevant authorities' while reassuring the public that 'at no point has passenger safety or aviation security been compromised'. They also noted that 'airport operations remain unaffected and customer parking services continue to operate normally.'

Concluding the statement, the representative noted that 'we would like to reassure customers that Manchester Airport Group takes the security of customer information extremely seriously and we apologise for any inconvenience or concern caused.'

Why Airports Hold So Much Customer Data

Highlighting the sheer scale of the incident, Gordons law firm partner Lauren Wills-Dixon pointed out that 'airports sell a number of services including lounge access, parking and fast-track bookings. Wi-fi access also requires customers to input their data'.

She explained that 'as a result, operators will hold large amounts of customer data and this, together with the increased use of technology, only increases the threat of a cyber-attack.'

The incident comes amid mounting pressure on the firms and managers behind national infrastructure to strengthen their digital defences.

Flights faced delays and cancellations across three major European hubs, including London's biggest airport, Heathrow, following a digital strike reported by the firm providing their boarding and check-in software.

Earlier this month, Iranian-affiliated hackers were accused of carrying out a digital strike that forced a temporary shutdown at a British power facility. Officials clarified that the event affected a minor generator, and that the broader energy grid never faced any genuine danger.

UK Firms Face Growing Cyber Threat

A surge of major digital breaches has struck British firms over the past year, from an incident that halted Jaguar Land Rover's production lines for weeks to similar attacks targeting Marks & Spencer, Harrods and the Co-op grocery network.