Cyber Security Advisory: Manchester Airports Group Data Security Incident

28th August 2026, 2:20 pm

Manchester Airports Group (MAG) has confirmed a cyber security incident involving customer data associated with airport parking, lounge bookings, Fast Track services and airport WiFi registrations. MAG states that payment card details were not held in the affected system, but customer contact information including email addresses, phone numbers, vehicle registrations and postcodes may have been accessed.

What Could Happen Next?

Whenever criminals obtain customer contact information, there is an increased risk of:

  • Phishing emails
  • Fake SMS messages (smishing)
  • Scam phone calls (vishing)
  • Fraudulent booking updates
  • Fake refund or payment requests
  • Impersonation of airport customer service teams

These communications may appear genuine because they could reference your travel plans, airport parking, vehicle registration or booking details.

Be on the Lookout For

Emails claiming a booking needs updating

Text messages asking you to click a link

Phone calls requesting payment or account information

Messages asking you to install software or verify your identity

Unexpected requests for passwords or Multi-Factor Authentication (MFA) codes

Remember, Legitimate organisations will never ask for your passwords, MFA codes or banking PINs via email, text message or phone call.

What Should You Do?

  • Verify unexpected messages independently.
  • Visit the airport website directly rather than using links in emails or texts.
  • Be cautious with any communication relating to airport services or bookings.
  • Ensure MFA is enabled on your important accounts.
  • Keep devices updated with the latest security patches.

How to Report Suspicious Activity

If you receive a suspicious email, text message or phone call:

Consumers

Forward suspicious text messages to 7726 (free UK spam reporting service).

Report phishing emails to [email protected].

Report fraud attempts to Action Fraud via https://www.actionfraud.police.uk/

Business Users Report the communication to your internal IT team immediately.

Do not click links, open attachments or respond until it has been verified.

If you accidentally interacted with a suspicious message, notify IT as soon as possible so appropriate action can be taken.

Cloud4’s Advice

At present there is no public evidence that customer devices have been compromised through this incident. However, the information reportedly accessed could be used to create highly convincing phishing and social engineering attacks. Remaining vigilant over the coming weeks is the best defence.

Think before you click. Verify before you trust. Report anything suspicious.

Next Article

UK AIDS Memorial Quilt Goes On Display At The Kimpton Clocktower For Manchester Village Pride

To mark the Manchester Pride period and honour the lives of those lost to the HIV and AIDS epidemic, Block […]
Read Article