Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports

Manchester Airports Group disclosed that an unauthorised third‑party accessed booking‑system data for roughly 8.7 million passengers across Manchester, London Stansted and East Midlands airports. The breach exposed email addresses, phone numbers, vehicle registrations and postcodes, triggering privacy‑compliance concerns under SOC 2 and GDPR/CCPA.

LiveThreat™ Intelligence · 📅 August 28, 2026· 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
securityaffairs.com

Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports

What Happened — An unauthorised third‑party breached Manchester Airports Group’s (MAG) booking platform over the weekend of 25 August 2026, gaining access to personal data for roughly 8.7 million passengers who used car‑park, lounge, fast‑track or airport‑Wi‑Fi services at Manchester, London Stansted and East Midlands airports.

Why It Matters for Compliance & Audit Readiness

  • The incident illustrates a classic privacy breach that SOC 2 CC 5.2 (Privacy) and GDPR/CCPA obligations require you to detect, contain, and document personal‑data exposures.
  • Continuous evidence of data‑handling controls, consent management, and DSAR readiness is essential to demonstrate a defensible audit trail and avoid regulatory penalties.

Who Is Affected — Aviation & travel services; any organisation that collects booking‑related personal data (email, phone, vehicle registration, postcode).

Recommended Actions

  • Map the exposed data fields to SOC 2 privacy controls and verify that consent records and data‑retention policies are up‑to‑date.
  • Initiate a DSAR readiness review and capture evidence of incident‑response procedures, notification timelines, and remediation steps for audit purposes.

Technical Notes — Attack vector not disclosed; attackers accessed a customer‑management system storing booking details but no payment data. Source: SecurityAffairs

📰 Original Source
https://securityaffairs.com/197966/data-breach/cyberattack-on-uk-airport-operator-mag-exposes-data-of-8-7-million-customers-across-three-airports.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

A privacy incident is a question about your consent record.

CookiePLUS and Verisq AI Trust Operations keep consent, DSAR, and data-handling evidence continuously ready — so a data-exposure event finds you prepared, not scrambling.

See how Verisq AI Trust Operations handles privacy →