The Manchester Airports Group breach has left the personal data of 8.7 million customers sitting on the open internet, accessible to any criminal without the need to navigate the dark web, after the hacking group FulcrumSec refused a ransom rejection and published the dataset publicly.

Manchester Airports Group (MAG), which operates Manchester, East Midlands and London Stansted airports, confirmed the incident after becoming aware of it on Tuesday. Hackers accessed customer data over the preceding weekend, demanded a ransom, and were refused.

What the Manchester Airports Group Breach Actually Exposed

MAG’s initial communications pointed to email addresses, vehicle registrations and postcodes. Its own data security incident page adds phone numbers to that list. Have I Been Pwned lists the compromised categories more fully still: browser user agent details, geographic locations, IP addresses, names, purchases and email addresses, alongside vehicle registration plates.

The majority of email addresses came from passengers signing up to airport Wi-Fi. More detailed records, including vehicle registrations, derived from car-park bookings, lounge access arrangements and Fast Track purchases. Tech-insider.org notes that the 8.7 million figure represents customer records tied to those services, not necessarily 8.7 million distinct individuals, as repeat customers and multi-year booking histories may account for some of the total.

MAG confirmed that no bank or payment details were held on the compromised system. The group has also stated it will never contact customers unexpectedly to request payment card details, banking information or passwords.

A Leak Site on the Clear Internet Is the Unusual Detail Here

FulcrumSec published the stolen data on approximately 3 September 2026. The dataset, according to BBC News, is being offered free of charge through a website hosted on the clear internet rather than a dark-web leak site. That is unusual. Most ransomware groups use Tor-hosted sites that require specialist software to reach; hosting on the open web removes that friction entirely and makes the data available to a far wider pool of opportunists.

FulcrumSec described the release as ‘Half a terabyte, and every byte of it is pure PII.’ The raw figures back that up: approximately 86 GB compressed, expanding to roughly 640 GB extracted, according to Tech-insider.org’s reporting on the breach.

MAG told the BBC the identity of the hackers is known and the relevant authorities have been informed. Airport operations were unaffected throughout. Bitdefender reports that MAG temporarily suspended its online Manage My Booking service as a precaution, though car-park services and terminal operations continued normally.

The Regulatory Exposure MAG Now Faces

MAG’s three airports collectively serve around 61 million passengers a year. Even if the 8.7 million breached records do not map one-to-one to individuals, the scale will focus the Information Commissioner’s Office (ICO) sharply on the group’s response.

UK GDPR requires breach notification to the ICO within 72 hours of awareness. MAG said it only became aware of the hack on Tuesday; the timeline of its notification to the regulator will matter. Shattered.io’s analysis of the incident notes that the regulation carries a theoretical maximum penalty of £17.5 million or 4% of global annual turnover, whichever is the higher figure.

That ceiling is rarely reached in practice, but the ICO has shown it is willing to issue substantial fines where large volumes of personal data have been mishandled. British Airways was fined £20 million in 2020 after a breach affecting 400,000 customers; MAG’s exposure is more than twenty times larger by record count.

MAG said in a statement: ‘We would like to reassure customers that Manchester Airport Group takes the security of customer information extremely seriously and we apologise for any inconvenience or concern caused.’

Customers are urged to be vigilant about unsolicited emails, texts or calls, and to avoid opening attachments from unknown senders. The ICO’s formal assessment of the 72-hour notification timeline is the next concrete marker in how this plays out for the group.

Shares: