You connected to airport Wi-Fi. Someone kept the receipt
Manchester Airports Group says hackers took customer data — including the details people typed in to get free Wi-Fi at Manchester, Stansted and East Midlands. Local media put the number as high as 8.9 million travellers.
You land, you're tired, you tap "connect to free Wi-Fi" and type in your email and phone number without thinking about it. That form is now part of a data breach. Manchester Airports Group — the UK's biggest airport operator, owner of Manchester, London Stansted and East Midlands — said on 27 August 2026 that intruders got into its systems and took customer data, and that the stolen material includes Wi-Fi sign-ups.
It doesn't stop at Wi-Fi. MAG says the data also relates to car park, lounge and Fast Track bookings. The compromised details are email addresses, phone numbers, vehicle registration numbers and postcodes. Payment card details were not accessed, the company says, and flights and parking kept running normally. MAG has not said how many people are affected. Local media reported the data of up to 8.9 million travellers may have been exposed, citing private MAG statements — a figure BleepingComputer says it could not confirm.
Nothing in that list looks dangerous on its own. Together it's a very good starting kit for someone who wants to sound like they know you. Your email, your mobile, the postcode you live in, and the registration plate of the car you left in the car park. That last one is the unusual part — most breaches don't come with your number plate attached.
Think about the message that writes itself: "Your parking session at Manchester Airport for vehicle [your actual plate] is unpaid. Pay within 24 hours to avoid a fine." You'd believe it. Most people would.
Card numbers get cancelled in ten minutes. Your number plate is yours for years.
That's the quiet mechanic here. A stolen card is a problem with an expiry date. A stolen set of facts about your ordinary life has no expiry date, and it gets more valuable when it's combined with the next leak, and the one after that. MAG says it will never ask customers for card details, banking details or passwords — which is exactly the sentence to remember, because whoever contacts you next will ask for precisely those.
Anyone who has flown through Manchester, Stansted or East Midlands — the three airports handle over 66 million passengers a year between them. That's students flying home on the cheap ticket, people who parked the car for a week and paid by app, and the 40,000 people MAG employs. And more broadly: everyone in their twenties and thirties who signs up for free Wi-Fi in a café, a train, a hotel or a terminal several times a month and has never once wondered where that email address ends up. It ends up in places like this one.
MAG says it contacted impacted customers directly but has not published a number, so the 8.9 million figure remains unconfirmed. Two things to watch: whether MAG puts an official count on it, and whether its online Manage My Booking service comes back — it's temporarily suspended right now, with travellers sent to the phone line instead. As of BleepingComputer's report, no ransomware or extortion group had publicly claimed the attack. Nobody has named a date for any of it.
The Wi-Fi form isn't security. It's marketing — a way to get your email in exchange for twenty minutes of internet. Nobody ever told you it was being kept, and nobody asked whether it was worth keeping. Somewhere in a database, a bored moment at gate 14 turned into a permanent record of your car, your phone and your postcode.
Sources: Manchester Airports Group statement as reported by BleepingComputer (Bill Toulas), 27 August 2026.
Утечка у крупнейшего оператора аэропортов Британии показывает, во что превращается безобидная регистрация в аэропортовом Wi-Fi: почта, телефон, номер машины и индекс — готовый набор для адресного мошенничества, и до 8,9 млн человек могут оказаться в списке.
Written by THE TELL’s AI newsroom. how we work · corrections