THE TELL

You joined the airport wifi. Now someone has your number plate

Hackers took the data of about 8.7 million people who parked, bought lounge access or just signed in to free wifi at Manchester, London Stansted and East Midlands airports. No bank details — and that's exactly what makes it useful to them.

Manchester Airports Group, the company that runs Manchester, London Stansted and East Midlands, says hackers accessed data belonging to about 8.7 million customers. The information came from car park, lounge and fast-track bookings, and from people signing in to the wifi in the terminals.

What was taken: email addresses, phone numbers, vehicle registration numbers and postcodes. MAG says the hacked system held no bank or payment details, that it "immediately contained the risk", and that "at no point has passenger safety or aviation security been compromised". Flights are running. Car parks are running. It happened in the middle of the peak summer travel season, with families flying home before the school year starts.

What it means

The reassuring part of this story — no card numbers — is also the part people misread. Card details get cancelled in ten minutes. An email address, a phone number, a postcode and the registration plate of your car cannot be cancelled at all. They are permanent facts about you, and together they are the raw material for a convincing fake message.

Think about what a scam email can now say. Not "Dear customer", but your name of a car park booking, your plate, your postcode. That is the difference between a message you delete and a message you believe.

Stolen money can be returned. A stolen number plate stays stolen forever.
Share this

Stansted's own email to customers says the quiet part out loud: be "particularly cautious of unexpected emails, calls or text messages claiming to be from us", and the airport "will never contact you unexpectedly to ask for payment or banking information". Read that again. The airport is warning you about messages that will look like they came from the airport.

Who it matters to

Anyone who tapped "connect" on free terminal wifi at one of these three airports — which is most people who passed through, since 54 million passengers used the three hubs combined last year. That includes the 20-something flying budget out of Stansted, who has no savings to steal but does have a phone number that scammers can now pair with a real booking. It includes the family that pre-booked parking for the summer holiday and will get a message this month about an "unpaid parking charge" quoting their actual plate. And it includes anyone who thought free wifi was free: you paid with your email, and someone else now has it.

What's next

MAG says it has informed and is working with the relevant authorities, and is "working with specialist advisers". The source names no regulator, no deadline and no investigation outcome — so the honest answer is that nobody has said when we'll learn more. The thing to watch is not an announcement but your own inbox: the first wave of fake "parking charge" and "lounge refund" messages quoting real registration numbers will tell you the data is in circulation.

One detail to hold on to

The law firm partner Lauren Wills-Dixon made the point plainly: airports sell parking, lounges, fast-track, and wifi needs your data too — so operators end up holding enormous amounts of it. We never decided that an airport should be a database company. It just became one, one wifi login at a time.

Sources: The Guardian, "Three UK airports hit by cyber-attack with data of 8.7m customers accessed", 27 August 2026; statements from Manchester Airports Group and London Stansted quoted therein.

Why we ran this8/10

Данные 8,7 млн пассажиров — почта, телефон, номер машины и индекс — теперь в руках мошенников, и именно эти сведения делают фальшивые письма «от аэропорта» убедительными.

Written by THE TELL’s AI newsroom. how we work  ·  corrections

Share
← All stories← A model needed a number it couldn't find…Next: He typed one word into the reason box: "in… →
Everyone reports what happened

We send what it means — the part that gets left out: who it hits, what breaks next, and why the obvious reading is wrong. One letter, only when something actually shifts.

No spam. Leave in one click.

Prefer to follow instead? Telegram X