UK Airport Wi-Fi Signups Became an 8.7 Million Leak
Manchester Airports Group says 8.7 million customer records were taken from Wi-Fi, parking, lounge, and fast-track systems. After MAG refused a ransom.

TL;DR
- —You tap accept, type an email, and wait for the boarding group.
- —The form feels like a captive portal, not an identity system.
- —On 27 August 2026, MAG said an unauthorized party had obtained customer data tied to Manchester, London Stansted, and East Midlands airports.
Free airport Wi-Fi is a habit. You tap accept, type an email, and wait for the boarding group. The form feels like a captive portal, not an identity system. Manchester Airports Group found out the difference. On 27 August 2026, MAG said an unauthorized party had obtained customer data tied to Manchester, London Stansted, and East Midlands airports. The company put the number at about 8.7 million customers. MAG told the BBC the attackers demanded a ransom and that it refused to pay. It also said passenger safety and aviation security were not compromised, and that the hacked systems did not hold bank or payment details. On 2 September, BBC and Computer Weekly reported that the stolen data had been posted online after the ransom attempt failed. What MAG says was taken MAG's first public account was specific about the sources: In-airport Wi-Fi signups
Car park bookings
Lounge and fast-track bookings Fields it named: email addresses, phone numbers, vehicle registrations, and postcodes. MAG said the "vast majority" of affected people were in the email-only bucket from Wi-Fi. That split is doing a lot of work. An email from a captive portal is already enough for phishing. Add a plate, a postcode, and a parking booking and you have a story that sounds like it came from the airport. What showed up after the leak Have I Been Pwned reviewed published material and, according to BBC and Computer Weekly, found email addresses, phone numbers, addresses, licence plate numbers, purchasing history, and browsing-device data. SecurityWeek later reported HIBP's parse at about 8.8 million email addresses and phone numbers. Those are HIBP and press counts of a published dump, not a MAG census. They are still the best public measurement of what left the building. The extortion group FulcrumSec claimed the theft. BleepingComputer reported that the group said it stole about 86 GB compressed, then later that extracted files totaled roughly 640 GB. The same outlet reported a claim that access came from airport-specific Iterable API credentials exposed in client-side JavaScript, and that the material included records related to upcoming travel. MAG has not publicly confirmed that access path. Treat the JavaScript-key claim as a threat-actor statement until MAG or an incident report says otherwise. The useful part of the claim does not depend on the brand name Iterable. If a marketing stack's secret is in the page, the page is the door. Why travel-adjacent PII is a scam kit This is not a password dump. It is a context dump. A scammer with an email plus a recent parking booking can write: "Your Stansted booking needs a payment update." A scammer with a plate can write: "ANPR captured an unpaid stay." A scammer with a phone number can skip email filters entirely. MAG told customers to be cautious about unexpected emails, calls, or SMS claiming to be from the group. That is the correct warning. It is also late for anyone whose Wi-Fi email has been sitting in a marketing list for years. FulcrumSec, via Computer Weekly, claimed it would not release a slice of upcoming travel schedules for about 200,000 people. Do not outsource your threat model to the attacker's press release. If that data existed in the same systems, assume someone else can copy a copy. What to do if you used MAG Wi-Fi or parking Treat MAG-branded messages as hostile until you reach the company through a URL you already know.
If you reused that airport email password anywhere, change it. The password exposure check is a start.
Watch for plate- and booking-themed SMS. Those are not "MAG support."
If Have I Been Pwned later lists your address, use that as a signal to lock down recovery codes, not as a complete map of what was taken. MAG said existing bookings remained valid and operations continued. That is about planes. It is not about your inbox. The pattern UK retailers and transport operators have had a rough two years of extortion leaks. MAG is the airport version of the same design: collect identity for a convenience feature, keep it, then negotiate with whoever copies the keep. Wi-Fi signup forms train people to hand over an email for a connection they already paid for with a ticket. When that table leaks, the convenience fee is paid again, by the passenger, in phishing risk.