top of page

8.7 Million Airport Customers Had Their Data Stolen. Were You One of Them?

2 days ago
3 min read
Glowing keyboard keys with phishing, @, and QWAS letters on a dark cyber background.

Introduction

In August 2026, Manchester Airports Group (MAG) announced a cyberattack that affected about 8.7M customers. The company owns Manchester, London Stansted, and East Midlands airports.

The attackers did not get customers’ banking or payment information. Instead, the stolen information included email addresses, phone numbers, postal codes, and vehicle registration numbers linked to airport parking, lounge and Fast Track bookings, and Wi-Fi registrations.

At first glance, that might sound relatively harmless. Unfortunately, cybercriminals don’t always need your credit card number to cause problems.

What Can Criminals Do With Basic Information?

Imagine receiving a text message a few weeks after returning from vacation:

“Manchester Airport Parking: We noticed an issue with your recent parking payment. Please verify your vehicle registration and payment information.”

In this scenario, you recently used airport parking. In fact, the message knows which airport you visited. It might even know your vehicle registration and other personal information.

Suddenly, that message seems a lot more believable. In fact, this shows one of the biggest risks after a data breach. Cyber-criminals can use legitimate information about you to make their targeted attacks much harder for victims to recognize.

What to Know About Spear-Phishing

Generic phishing attacks cast a wide net. For instance, you’ve probably received obviously fake emails claiming that your Netflix account was suspended when you don’t even have a Netflix account.

Spear-phishing works much differently.

Instead of sending the same message to thousands of random people, bad actors use information they already know about you to make their message more convincing. An attacker who knows your name, phone number, email address, postal code, and a company you’ve recently patronized can make you believe that you’re speaking with a legitimate representative.

This lets threat actors impersonate that company and ask you to reset your password, confirm a payment, or provide additional information. That first batch of stolen information then becomes bait to steal more valuable account information.

Data From Different Breaches Can Also Be Combined

Unfortunately, your information likely exists in more than one stolen database. That complicates the situation. One breach might expose your email address and phone number, while another leaks an old password, and a third reveals your date of birth or home address.

Cybercriminals can combine information from different sources to create a much more complete picture of you.

This is why seemingly minor breaches still matter.

An email address might not seem particularly sensitive on its own, but combine it with your phone number, location, purchase history, and a password you reused elsewhere, and the situation can change quickly.

What Should You Do After a Data Breach?

If a company tells you that your information was exposed, pay attention to exactly what was reportedly stolen. Then think about how someone could use that information against you.

A few simple precautions can help.

  • Unexpected messages claiming to come from the breached company should raise suspicion.

  • Never share passwords or security codes with someone who contacts you unexpectedly.

  • Use password managers to protect your sensitive accounts.

  • Go directly to the company’s website instead of clicking links in emails or text messages.

  • Change any exposed passwords, especially if you reused them elsewhere.

  • Enable multi-factor authentication or passkeys whenever possible.

  • Watch your accounts for unusual login attempts.

Most importantly, expect spear-phishing attempts after a breach. The attacker may already know enough about you to sound real.

Conclusion

Stolen data doesn’t need to include your credit card number to create a cybersecurity risk, as the Manchester Airports Group breach illustrates. Sometimes criminals steal basic information first and then use it to convince you to provide the sensitive information they actually want. That means the email or text you receive after a breach may know surprisingly specific details about you. You still can’t assume that makes it legitimate.

When an unexpected message asks you to click, pay, log in, or provide additional information, you should always verify the request another way first.

The scammer may know who you are, but that doesn’t mean you have to give them any private information.

Comments


bottom of page