Your guest Wi-Fi sign-up form is a customer database
Updated 30 August 2026, 21:10 (BST). This filing was published on 27 August, when MAG's own statement was the only source and no attacker, scale, or timeline was public. It has been revised to add the figure of about 8.7 million people affected, and the FulcrumSec claim of 86 GB, including booking, travel, and device data that goes beyond the four fields MAG listed. The original text said no attacker, volume, or timeline had been made public, which is now out of date. It also said card fraud was not the risk; that still matches both MAG's statement and what reviewers saw in the samples, but the exposure around it is wider than first described.
If your business offers guest Wi-Fi and asks people for an email address before it connects them, you are running a customer database. It probably was not set up by anyone who thought of it that way. It may have been installed by the company that fitted the router, or switched on inside a marketing tool because someone wanted a mailing list. It sits outside whatever you think of as your real systems, and nobody reviews it.
Manchester Airports Group has just demonstrated why that matters.
What MAG has said
On 27 August the group published a statement across its three airport sites, Manchester, Stansted, and East Midlands. An unauthorised third party obtained a quantity of customer data. MAG says it contained the incident, engaged specialist advisers, and notified the relevant authorities.
The interesting part is where the data came from. In MAG's own words, it "relates to car park, lounge, and Fast Track bookings and in-airport WIFI sign-ups". The fields taken were email addresses, phone numbers, vehicle registrations, and postcodes. MAG states that neither the group nor the system accessed holds customers' bank or payment details.
It also says passenger safety and aviation security were never compromised, and that flights and parking are running normally. As a precaution it has temporarily suspended online booking amendments, with a phone line for changes needed inside 72 hours. Affected customers have been contacted directly.
A MAG spokesperson has since put the number of people affected at about 8.7 million, saying that in the vast majority of cases the only field exposed was an email address.
On 30 August an extortion group calling itself FulcrumSec claimed responsibility, saying it took roughly 86 GB and sharing samples with BleepingComputer as proof. BleepingComputer validated one traveller's record against their known purchase history: it correctly listed previous Fast Track purchases, booking and arrival times, the terminal used, amounts paid, and total spending. The wider samples are reported to contain booking references, parking dates and times, prices, historical spending, IP addresses, approximate locations, and device information. No card or bank details were seen.
Two claims go further and are not verified. The group says it holds nearly 200,000 records covering travel booked for the rest of 2026, and that it got in using credentials for a marketing platform left exposed in the website's own client-side JavaScript. BleepingComputer could not confirm the size of the dataset or how the attacker got in, and MAG declined to address the specifics, saying only that it has contacted everyone affected including those with upcoming bookings. MAG is understood to have refused a ransom demand.
It is worth being precise about how this differs from the original disclosure, because it is not simply more fields. MAG's four fields describe how to contact someone. The validated record describes their movements: which terminal, what time, what they paid, how much they had spent in total over time, and what BleepingComputer described as the apparent purpose of the trips. If the future-travel claim holds, it also covers where they are going next.
That is a change in kind, not degree. Contact details let someone message you. A travel history says where you were and roughly why, and a forward booking says when your house is empty. Those are different things to lose, and the second sort is far harder to make right after the fact. You can change an email address.
None of this makes MAG's statement wrong. The four fields it listed do appear in the samples, and no card or bank data was seen. But it was an incomplete description of what a person actually lost, and the reason to notice that is the pattern rather than the airport: peripheral systems accumulate behavioural detail nobody ever decided to collect.
At about 8.7 million people, this is the largest known customer data breach at a British airport operator.
The systems nobody counts
Look at that list again. Car parking. Lounge bookings. Fast Track. Guest Wi-Fi sign-ups.
Not one of those is what anyone would call a critical airport system, and MAG is right that none of them touches aviation security. That is exactly the point. These are the peripheral systems, the extras bolted on around the edges of the main operation, frequently bought separately, run by a different supplier, and integrated years ago by someone who has since left.
Small businesses have the same shape. The core thing you do is protected because it is obviously important. Meanwhile there is a booking widget, an events sign-up, an old prize-draw form, a review request tool, and a Wi-Fi splash page, each of which has been quietly accumulating names, emails, and phone numbers for years. Ask most owners how many personal records they hold and they will think of the main system. The answer is usually the main system plus five things they forgot.
Guest Wi-Fi is the clearest example because it rarely feels like data collection at all. The customer wants the internet, the form asks for an email in exchange, and everyone treats it as a formality. But every one of those sign-ups is a person, and under data protection law you are responsible for the lot.
"No payment details" is doing a lot of work
The reassurance in the statement is genuine as far as it goes: MAG says no card numbers were taken, so direct card fraud is not the immediate risk. It is worth being clear about what was taken instead, because the combination is more useful to a criminal than it first sounds.
An email address, a phone number, a postcode, and a vehicle registration is a strong kit for a convincing text message. The registration is the unusual one. Most scam texts about parking are fired off blind, and people ignore them because nothing in the message proves the sender knows anything. A text that names your actual number plate, arriving in the weeks after you actually parked at that airport, is a different proposition. So is a refund offer that cites the right booking type.
A UK postcode makes this worse than the equivalent US leak. A typical small-user postcode covers around 15 addresses, and some cover a single one, so it is close to naming the street. Add the vehicle, the airport, and the parking dates, and a scam message can reference all of it. If the claims about future travel hold up, a message that knows when you are flying is harder still to dismiss.
That is the realistic next step here, and it is worth telling colleagues and customers about plainly: expect texts and emails referencing parking charges, drop-off fees, or booking refunds, and treat anything asking for card details as false. MAG has said it will never contact customers unexpectedly to request card details, banking information, or passwords. Nobody legitimate will. If a message looks like it might be real, go to the organisation's website yourself rather than following the link.
What to check in your own business
Three things, none of which needs a budget.
Write down every place you collect personal data. Not the systems you consider important, all of them. The Wi-Fi portal, the contact form, the booking tool, the events list, the old campaign nobody has switched off. If you cannot produce that list, you cannot protect it, and you could not tell people what had happened if it leaked.
Ask who actually holds it, and where. For each one, who is the supplier, does the data sit with them or with you, and what would they tell you if they were breached. Peripheral systems tend to be someone else's platform, which means your incident would start with their phone call.
Stop collecting what you do not use. The cheapest fix in security is not holding the data. If nobody has ever emailed the guest Wi-Fi list, turn off the field that builds it. A form that asks for a vehicle registration when it does not need one is creating risk for free.
The lesson from MAG is not that airports are careless. It is that the systems most likely to leak your customers' details are the ones nobody thinks of as systems at all.
How Steelwise can help
Building an honest list of everywhere your business holds personal data, and working out which of those places would hurt if it leaked, is a short and well-defined piece of work. Get in touch if you would like help with yours.
Further reading
- Manchester Airports Group statement on the incident
- NCSC: Data breach guidance for individuals
- NCSC: Phishing scams, how to spot and report them
- ICO: Personal data breaches