Manchester Airports Group refuses ransom after cyberattack hits 8.7 million passengers
Manchester Airports Group rejected an extortion demand following a data breach affecting 8.7 million passengers across Manchester, Stansted, and East Midlands airports, with flight operations remaining unaffected.
Extortion attempt and refusal
A criminal hacking group demanded an undisclosed ransom from Manchester Airports Group after accessing personal records belonging to 8.7 million customers. The digital intrusion occurred over the preceding weekend and was first disclosed by the operator on 26 August 2026. The airport group, which manages Manchester Airport, London Stansted Airport, and East Midlands Airport, refused to pay the extortion sum and aligned its actions with guidance from British law enforcement. The cybercriminal syndicate responsible is known to authorities in the United Kingdom and has carried out similar intrusion campaigns against commercial entities worldwide this year. Forensic evaluations found no indication of involvement by foreign states. Manchester Airports Group confirmed that the unauthorized entry point was identified and closed rapidly after detection.
Manchester Airports group has been subject to a cyber security incident by an unauthorised third party.
Compromised booking data and digital services
The compromised records were primarily email addresses collected when passengers logged into terminal Wi-Fi networks across the three hubs. A smaller subset of records contained customer telephone numbers, residential postcodes, and vehicle registration plates linked to airport parking, lounge access, and Fast Track reservations. Manchester Airports Group confirmed that its breached systems did not store bank account details or credit card information, preventing the loss of financial assets. The group, which employs more than 7,000 people and operates the CAVU digital travel services business, temporarily shut down its online Manage My Booking platform. Customers needing to adjust existing reservations were instructed to complete changes by telephone.
| million passengers | |
|---|---|
| Manchester Airport | 32 |
| London Stansted Airport | 30 |
| East Midlands Airport | 4 |
Operational continuity and institutional response
Flight schedules, runway operations, and passenger processing across all three locations continued without disruption throughout the breach. Manchester Airports Group confirmed that physical aviation safety, terminal security, and car park facilities remained fully functional. The company reported the breach to the National Cyber Security Centre and lodged a formal notification with the Information Commissioner's Office, the data protection regulator for the United Kingdom. External cybersecurity advisers were brought in to investigate the intrusion and bolster digital defences. Security assessments confirmed that the stolen data had not appeared on dark web marketplaces.
At no point has passenger safety or aviation security been compromised.
Passenger scale and security recommendations
The three regional hubs handle substantial travel volumes, with Manchester Airport serving over 32 million passengers, London Stansted recording approximately 30 million, and East Midlands handling around 4 million passengers over the past year. Manchester Airports Group notified affected customers by email on the morning of 27 August 2026, advising them to exercise vigilance regarding phishing messages. The notification instructed travellers that the operator will never make unsolicited contact requesting payment credentials. Security guidance distributed after the breach advised individuals to update account passwords and use independent breach-verification platforms to monitor their exposed credentials. The incident follows earlier cyberattacks against British commercial and cultural bodies, including Jaguar Land Rover, Marks and Spencer, Harrods, Co-op, and the British Library.
| Preceding weekend | Unauthorised third party accesses customer systems across three airports |
|---|---|
| 2026-08-26 | Manchester Airports Group publicly discloses the cyber security incident |
| 2026-08-27 | Operator sends email notices advising passengers on phishing risks |
| 2026-08-28 | Reports confirm criminal gang demanded a ransom and operator refused to pay |
Sources
- Hacker dietro il cyberattacco agli aeroporti britannici, chiesto un riscatto - Notizie
ANSA.it · Aug 28 - ++ Cyberattacco contro tre aeroporti in Gb, 'hacker hanno chiesto riscatto' ++ - Notizie
ANSA.it · Aug 28 - Attacco informatico contro tre scali inglesi: gli hacker chiedono un riscatto
Rai news · Aug 28 - Cyberattacco aeroporti nel Regno Unito, hacker chiedono un riscatto
Adnkronos · Aug 28 - Gb, gruppo hacker attacca tre aeroporti e chiede il riscatto
Tgcom24 · Aug 28 - Atac cibernetic asupra a trei aeroporturi britanice. Datele unor pasageri au fost accesate, dar zborurile nu au fost afectate
Ziare.com · Aug 28 - How to check if your details were stolen in Manchester Airport data breach
The Independent · Aug 28 - Nearly 9 million users hit in cyberattack on UK's biggest airport owner - email addresses, phone numbers, vehicle registrations and postcodes all stolen
TechRadar · Aug 28