Manchester Airports Group hit by cyberattack, data of 8.7 million customers accessed

Emails, phone numbers, vehicle data affected as group suspends online booking system

Manchester Airports Group hit by cyberattack, data of 8.7 million customers accessed

Cyber

By Matthew Sellers

Manchester Airports Group (MAG), the owner of Manchester, London Stansted and East Midlands airports, has confirmed a cyberattack in which an "unauthorised third party" accessed the personal data of approximately 8.7 million customers.

What we know so far

MAG said it became aware of the intrusion on Tuesday and moved to contain it immediately. The data taken relates to car park, lounge and Fast Track bookings, plus sign-ups for the airports' free Wi-Fi networks, meaning email addresses, phone numbers, vehicle registration numbers and postcodes. For most of those affected, the exposure is believed to be limited to an email address picked up through a Wi-Fi sign-in.

No bank details or payment card information were held on the compromised system, MAG said, and flights, security and day-to-day airport operations remain unaffected. As a precaution, the group has temporarily suspended its online Manage My Booking service while the investigation continues. It is working with specialist advisers and the relevant authorities.

Customers are being contacted directly and told to watch out for follow-up phishing attempts using the stolen data.

Why it matters for insurers

Security specialists are already flagging the fraud risk this creates. Illumio's Raghu Nandakumara told Infosecurity Magazine the exposed data raises the risk of "targeted phishing and smishing attempts" that use real travel details to make scam messages look convincing. MAG has issued a similar warning, telling customers it will never contact them unexpectedly to ask for banking information.

For the insurance market, the bigger question is what happens next, and who ends up paying for it. MAG has not said whether it holds a dedicated cyber insurance policy, and its public statements so far have focused only on containment and customer notification. The timing puts the incident in the middle of a debate the London market has been having for the best part of a year, over whether aviation actually understands and prices its cyber exposure properly.

The last twelve months haven't been kind to that assumption. Last September's attack on check-in and boarding systems at Heathrow, Dublin and Brussels was traced to a breach at supplier Collins Aerospace and forced airports back onto handwritten boarding passes and manual bag tags. It also left insurers working out how "dependent business interruption" clauses would respond to a single supplier failure rippling across an entire sector. Insurance Business reported at the time that the episode renewed calls for policies that pay out automatically, along with tighter scrutiny of how supply-chain cyber risk gets underwritten.

MAG's disclosure also lands in the shadow of last year's run of retail breaches. Marks & Spencer, Co-op and Harrods were all hit within weeks of one another in spring 2025, with M&S facing losses estimated at up to £300 million and a cyber insurance claim expected to top £100 million, led by Allianz with Beazley among the other insurers on the layered programme. Co-op, by contrast, had no dedicated cyber cover in place at the time of its attack, a gap industry commentators have since pointed to as a cautionary tale for boards weighing up whether the premium is worth it.

The bill for getting this wrong

Whatever cover MAG does or doesn't have, research published earlier this year gives a sense of the financial exposure UK businesses are now carrying. A joint study by Gallagher and the Centre for Economics and Business Research put the total cost of cyberattacks to large UK businesses at £11.7 billion in 2025. Direct losses from disrupted trading were the single biggest item at £5.4 billion, followed closely by £3.7 billion spent fighting shareholder litigation. Lost intellectual property and other assets added a further £1.3 billion, regulatory fines came to £108 million, and reputational damage was put at £573 million, with roughly £339 million more lost as customers cancelled contracts or switched suppliers in the aftermath. Gallagher's Laura Parris has argued that boards have historically measured cyber risk in terms of downtime and IT recovery, but "the risk doesn't end when the attack is over."

Take-up of cover looks reasonably healthy at the top end of the market. Gallagher's research found 88% of large UK businesses now hold some form of cyber insurance, with 72% covered for business interruption and 76% for the forensic and data-recovery costs that follow an incident. Litigation cover is where policies are said to be far less consistent, which matters given legal costs were the second-biggest line item in Gallagher's tally.

Whether MAG's breach develops into anything approaching that scale remains to be seen. The absence of financial data limits the immediate fraud risk, and the group's swift containment and early engagement with authorities will count in its favour when the Information Commissioner's Office assesses the response. Under UK GDPR, organisations are expected to report notifiable breaches within 72 hours of becoming aware of them. MAG's own timeline, discovery on Tuesday, public confirmation and customer notification by Thursday, suggests it is aiming to stay on the right side of that clock.

Even a breach with no financial data attached still carries a cost. Notification exercises across 8.7 million records, credit-monitoring offers, forensic investigation, and the reputational hit of a headline like this one landing just as the August bank holiday travel weekend gets underway all add up. These are the kind of drawn-out costs Gallagher's research suggests boards have tended to underestimate. For brokers advising transport and infrastructure clients, MAG's breach is a reminder that critical national infrastructure is a standing target for attackers, and that policy wording needs to keep up.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!