Manchester airport

Manchester Airports Group data breach: hackers claim 86 GB of data was stolen

The Manchester Airports Group (MAG) data breach may be more extensive than first thought. Hacking group FulcrumSec has claimed responsibility for the attack affecting Manchester, London Stansted and East Midlands airports. According to media reports, samples of the allegedly stolen information appeared to contain more detailed customer, booking and travel data than MAG initially disclosed. 

What has FulcrumSec claimed?

FulcrumSec told BleepingComputer that it stole approximately 86 GB of information from Manchester Airports Group. The group reportedly provided samples of the data to support its claims. 

BleepingComputer said it was able to verify one record against a traveller’s known Manchester Airport purchase history. The information reportedly included previous Fast Track purchases, booking and scheduled arrival times, the terminal used, amounts paid, booking references and historical spending.  

The publication also reported seeing a 21.5 GB Manchester customer export containing profiles combining customer information with previous booking activity and marketing data. 

FulcrumSec has additionally claimed that the stolen material includes almost 200,000 records relating to upcoming travel during the remainder of 2026. According to the hackers, those records could contain dates, times and booking information linked to identifiable individuals. 

However, some of the hackers’ claims have not been independently verified. 

What additional information may have been exposed?

When MAG first disclosed the breach, it said the information accessed could include email addresses, phone numbers, vehicle registrations and postcodes. 

However, according to BleepingComputer, samples of the allegedly stolen information appeared to contain considerably more detail than MAG initially disclosed. 

This includes: 

  • Purchase and booking references 
  • Airport and product selections 
  • Prices and discounts 
  • Booking status  
  • Parking dates and times 
  • Previous spending  
  • IP addresses 
  • Approximate locations 
  • Device information
  • Customer engagement information.  

Why could travel information be particularly concerning?

Detailed travel information could potentially make phishing attempts and other scams more convincing. 

For example, someone who knows which airport you use, when you parked there or which services you purchased could potentially use those details in an email, text message or phone call designed to look genuine. 

Information about future travel could raise additional concerns because it may reveal when someone plans to be away. 

FulcrumSec itself reportedly acknowledged the potential for “real-world harm” and said it was considering withholding or redacting upcoming-travel information if it publishes stolen data. That does not mean the information will be published, or that it will be misused. But affected customers should continue to be cautious about unexpected communications. 

What has Manchester Airports Group said?

At the time of writing, MAG has not confirmed the hackers’ claims about the alleged 86 GB dataset or the suggestion that almost 200,000 upcoming travel records were obtained. 

MAG also says it is confident that effective measures have been taken to protect customers. The airport operator said all affected customers had been contacted, including customers with upcoming bookings who were offered additional support. 

It has also stressed that it will never contact customers unexpectedly to ask for payment-card details, banking information or passwords. 

Who is FulcrumSec?

FulcrumSec is described as a financially motivated data-extortion group that has been active since 2025.  

Groups of this kind steal information and threaten to publish it unless their demands are met. FulcrumSec has previously claimed responsibility for attacks involving other organisations, including LexisNexis, Novo Nordisk, Global Schools Group and Avnet. 

How many people are affected by the MAG data breach?

A MAG spokesperson previously reported that around 8.7 million customers had been affected, although it said only email addresses had been exposed for the “vast majority” of those people. 

Customers affected by the incident include people who used airport parking, lounge and Fast Track services or on-airport Wi-Fi at: 

  • Manchester Airport 
  • London Stansted Airport 
  • East Midlands Airport  

The latest claims suggest that some customers may have had significantly more detailed information exposed. 

What should affected customers do?

If MAG has contacted you to confirm that your information was involved, keep the notification and any further correspondence about the incident.

You should also be particularly cautious about emails, text messages and calls that appear to know details about your airport bookings or travel plans. Do not assume a message is genuine simply because it contains information that only an airport or booking provider might be expected to know. 

Avoid providing banking information or passwords in response to an unexpected contact, and be cautious about clicking links in unsolicited messages. 

Could the Manchester Airports Group data breach lead to compensation?

People may be able to seek compensation where an organisation has broken data protection law and they have suffered damage as a result. This can include financial loss or, in some circumstances, distress. 

At this stage, there has been no finding that Manchester Airports Group broke data protection law. The latest reports may, however, add to questions about the scale of the incident and exactly what information was accessed. 

As more information emerges, affected customers may gain a clearer picture of what data was involved, how it was accessed and what legal options may be available. 

Join the Claim connects consumers with SRA-regulated lawyers. Visit the claim page to check your eligibility if a claim is open with one of our trusted legal partners. If a group action has not yet been launched, you can register your interest and we’ll keep you informed if a partner firm decides to take a claim forward.  

This information is for general guidance only and does not constitute legal or financial advice.

You may also like:

BMW faces legal action over emissions-cheating software. Learn what the scandal involves, who is affected, and what it means for UK diesel car owners.
Capita’s data breach exposed pension holders’ personal data. Stay updated on the latest legal action, investigations, and regulatory responses.
Confused about Jaguar Land Rover DPF claims vs. Dieselgate? Learn the key differences, legal actions, and how to check if you qualify for compensation.

Latest news & insights

Did you know we have a newsletter?

Sign up for our newsletter to stay up to date.