Manchester Airports Group (MAG), operator of Manchester, Stansted and East Midlands airports, disclosed a data breach in August 2026 that was later claimed by the FulcrumSec hacking group. The attackers published personal data on roughly 8.7 million customers, including email addresses, phone numbers, vehicle registrations, parking history, Fast Track purchases and lounge bookings. MAG stated that passenger safety and aviation security were not affected.
While the exposed dataset does not appear to contain passwords, the combination of email addresses and phone numbers is prime material for targeted phishing and social-engineering campaigns. Attackers often leverage such leaks to craft convincing lures that harvest credentials or MFA codes, which can then be used against corporate or personal accounts.
What to take away: exposed contact data feeds credential-phishing pipelines. Affected users should be alert to travel-themed phishing, and organisations should treat leaked employee emails as elevated-risk targets and reinforce phishing-resistant authentication.