# What happened
Group (MAG), which runs Manchester Airport, London Stansted and East Midlands Airport, suffered a cyber security incident that allowed unauthorised access to data for about 8.7 million customers. MAG has sent emails today to everyone whose information was accessed.
# What data was accessed
Mag says hackers accessed records related to car park bookings, lounge and Fast Track bookings, and sign-ups for on-airport Wi‑Fi. The types of personal information identified in the investigation include email addresses, phone numbers, vehicle registrations and postcodes. MAG states the affected systems did not store customers' bank or payment card details.
# What MAG has done so far
MAG says it immediately contained the risk after detecting the incident. The company has engaged cyber security specialists and notified relevant authorities. Emails have been sent to all customers it believes were affected. MAG also confirms that all upcoming bookings remain valid and operational.
# Why you're receiving an email now
The messages you're seeing are the formal customer notification. They explain the nature of the incident, which specific types of personal data were accessed, and outline the steps MAG has taken. The emails instruct customers that they do not need to take any direct action beyond routine caution.
# What you should do next
- Be alert for phishing attempts that use the breach as a pretext. Scammers often follow breaches with fake messages that ask recipients to click links, open attachments, or provide financial information.
- If you get a suspicious message, do not click links or download attachments. Verify by contacting MAG through official channels on its website or through a phone number you trust.
# What MAG says about passenger safety and bookings
MAG has explicitly stated that passenger safety and aviation security were not compromised during this incident. It also says the hack did not affect customers' payments. All bookings held with MAG remain valid and unaffected by the security incident.
# Short checklist for people who received the email
- Do not reply with personal or financial information.
- If you used the same password elsewhere, consider changing it there and enable two-factor authentication where available.
- Keep an eye on accounts that could be targeted with social-engineering attempts using the exposed contact details.
# Bottom line
MAG has communicated that roughly 8.7 million customers had contact and booking data accessed. The group says it contained the incident, is working with specialists and authorities, and has emailed affected customers. The immediate risk to financial or aviation security appears limited, but recipients should remain vigilant for follow-up scams that attempt to exploit the exposed contact information.