Manchester Airports breach reaches 8.7 million customers. Two 72-hour clocks applied, and only one of them ever started
MAG has confirmed the breach and an extortion group claims 86 GB. The claim is the least useful number available: this group has had five breaches confirmed by victims and not one claimed volume ever corroborated. The question worth asking is which regulator's clock was running, and only the ICO's was, because the aviation reporting threshold is written in cancelled flights.
By Parminder Kumar Sharma · · 7 min read

What MAG has confirmed, and what it has not
Manchester Airports Group issued one statement, at 12:49 on 27 August 2026, and it has not materially changed since. The company says an unauthorised third party obtained customer data relating to car park, lounge, Fast Track bookings and in-airport WiFi sign-ups at Manchester, Stansted and East Midlands:
"Neither MAG nor the system accessed hold customers’ bank or payment details. The data that has been accessed includes customers’ email addresses, phone numbers, vehicle registrations and postcodes."
A MAG spokesperson put the figure at around 8.7 million customers, and said that for the "vast majority" the exposure is the email address alone. MAG also says the incident caused no operational disruption and that "at no point has passenger safety or aviation security been compromised".
Comparing the archived captures against the live pages, the only substantive edit since publication was a new FAQ added on 28 August offering free changes and full refunds to anyone who wants them. The description of the breach itself has never been revised. The three airport sites are not even in sync: Stansted still carries the pre-28-August wording.
That is the whole of what the company has said. It is worth setting beside what has actually been verified.
What you were told, and what was in one verified record
BleepingComputer validated one record by checking it against a traveller’s known Manchester Airport purchase history. It matched: previous Fast Track purchases, booking and scheduled arrival times, the terminal used, amounts paid, purchase references, total spending, and the apparent purpose of the trips. Across the sampled records the publication also observed IP addresses, approximate locations, device information and customer engagement data.
MAG has not acknowledged a single one of those fields. That gap, between a four-category disclosure and a demonstrably richer record, is the part of this story with evidence behind it.
The 86 GB is the weakest number in the story
The figure driving the headlines is an extortion group’s own claim. FulcrumSec, first observed in September 2025 and also tracked as "The Threat Thespians", says it holds roughly 86 GB, including a 21.5 GB Manchester export and around 200,000 records covering upcoming travel for the rest of 2026. BleepingComputer states plainly that it could not verify the size of the dataset, the scope of access, or the upcoming-travel claim.
Gigabytes are not people. There is no conversion between the two without knowing the schema, the encoding, the compression and how much of the volume is duplicated history. FulcrumSec’s own description works against a naive reading: an export of consolidated profiles combining identifiers with historical booking activity is exactly the shape where bytes and individuals diverge, because one traveller generates many rows.
The group’s track record makes this sharper than ordinary caution.
FulcrumSec claims, and what has actually been established
| Question | What the public record shows |
|---|---|
| Did a breach occur? | Several victims have confirmed intrusions, among them Novo Nordisk and LexisNexis Legal and Professional. None has ever denied a claim. |
| Was the claimed volume accurate? | Not one claimed volume has been corroborated or independently measured, in any case. |
| Has the group been caught inventing data? | No researcher has documented it fabricating or recycling data. |
Read that table carefully, because it cuts both ways. The non-confirmations are mostly silence from small private companies, not denials, and no researcher has documented this group fabricating or recycling data. Every large victim in a position to respond confirmed the intrusion. Thomas Willkan of Lab-1, who tracks the group, told Reuters they are "usually quite legit in terms of both their capabilities and also their claims".
So the picture is two-tier, and the distinction matters:
- "Did we get in?" has held up. Several victims have confirmed intrusions, and journalists have validated samples in more than one case, including the Manchester record.
- "How much did we take?" has never once been corroborated. Every byte figure this group has published is an uncontested assertion. Large victims confirm the intrusion and then decline to engage with the number.
No vendor has published a systematic test of whether its volumes are accurate, so this is not a claim that the group inflates. It is a statement that nobody has ever checked, and MAG has not either.
The 86 GB and the 200,000 upcoming-travel records sit squarely in the second category.
Two 72-hour clocks, and only one of them started
Here is where most commentary goes wrong. Two separate reporting duties apply to a designated Operator of Essential Services, both run for 72 hours, and they are routinely treated as one thing. They are triggered by different events and owed to different regulators.
Two 72-hour clocks, and only one of them started
Regulation 11(1) of SI 2018/506 requires an operator to notify
"any incident which has a significant impact on the continuity of the essential service which that OES provides"
and the significance factors are all disruption metrics: users affected by the disruption, duration, geographical area. The Department for Transport’s guidance sets the aviation thresholds numerically, and every one of them is expressed in cancelled flights. For an aerodrome of Manchester’s size the trigger is more than 20% of scheduled flights cancelled in a 24 hour period.
A theft of customer data cancels no flights. On the published law and guidance, the NIS clock never started.
That is why MAG’s repeated insistence that there was no operational disruption is doing regulatory work as well as reputational work. Both things can be true at once.
MAG is in scope for the regime. Its own Annual Report and Accounts 2026, approved by the board on 30 June, states that NIS "applies to the Group as an Operator of Essential Services" and names the Civil Aviation Authority as the competent authority. That description is incomplete: Schedule 1 of the Regulations designates the Secretary of State for Transport and the CAA acting jointly, and the Department for Transport’s guidance directs notifications to its own Cyber Compliance Team, which then shares them with the CAA. There is no public register of designations, so per-airport status cannot be confirmed independently, but against the statutory threshold of ten million terminal passengers the CAA’s own 2025 statistics put Manchester at 32,061,307 and Stansted at 29,758,490, with East Midlands well below at 3,955,756.
The Article 33 clock did run. On the reported timeline MAG became aware on Tuesday 25 August, which puts the deadline at some point on Friday 28 August. The company told the public on 27 August, and the ICO confirmed on 28 August that it had received a breach report. Nothing visible suggests a timing problem.
The law is about to close exactly this gap. The Cyber Security and Resilience Bill, which had its Lords second reading on 14 July 2026 and enters Grand Committee on 1 September, would replace regulation 11 with a significance test whose new factor (e) asks
"whether the confidentiality, authenticity, integrity or availability of data relating to users of the essential service has been, is being or is likely to be compromised"
and would compress the first notification from 72 hours to 24. It is a Bill, not an Act. An identical incident after commencement would look very different.
What the ICO does next, judged on its own record
The instinct is to expect a large fine. The regulator’s own record points the other way, and the closest comparator is almost exact.
easyJet disclosed a breach affecting around nine million customers in May 2020. The ICO investigated, and then closed the case. Its own letter of 17 August 2023, case reference INV/0250/2020, signed by Deputy Commissioner Stephen Bonner, says:
"the Information Commissioner has exercised his administrative discretion to de-prioritise this case … The Commissioner does not consider that pursuing enforcement action in this case is currently the best use of the ICO’s limited legal and investigative resources … We now consider this case closed."
easyJet’s own audited accounts for the year ended 30 September 2023 confirm it: "The ICO has advised in this financial year that no further action will be taken and the investigation against the Group is now closed."
Nine million customers, no fine, no enforcement action of any kind. MAG has 8.7 million.
Where the ICO has acted on security, it has been slow. Advanced Computer Software was fined in March 2025 for a ransomware incident of August 2022, roughly 31 months later. Capita settled at £14m in October 2025 over an attack in April 2023, about 30 months. Sixteen months after the 2025 retail attacks, there is still no ICO action against M&S or the Co-op.
9m
easyJet customers affected
Case closed in August 2023 with no enforcement action, on resource-prioritisation grounds.
£45m to £14m
Capita, proposed against final
Even the ICO’s largest security settlement landed at under a third of the sum first proposed.
~30
months from attack to ICO fine
Advanced took about 31 months, Capita about 30. On that precedent a MAG outcome is a 2028 question.
The absence of an ICO statement about MAG carries no weight either way. The ICO does not publish a register of reported breaches, only aggregate quarterly statistics, and it says outright that larger and more serious cases are transferred elsewhere and excluded from those figures. It names organisations when it takes formal enforcement action, and not before.
What to do this week
Take this with you
If your organisation is a designated Operator of Essential Services
- Work out which of your clocks a data-only incident actually starts. If the answer is the ICO one and not your sector regulator’s, write that down now rather than deciding it at three in the morning during an incident.
Take this with you
For everyone
- Read the Cyber Security and Resilience Bill before it commences. If it passes in its current form, the first notification drops to 24 hours and confidentiality of user data enters the significance test. A 24-hour duty is an operational change, not a legal footnote.
- Audit what your marketing and analytics platforms hold about a customer, not just what your privacy notice describes. The distance between MAG’s four disclosed categories and the fields in one authenticated record is the distance between a booking system and a consolidated customer profile.
- Check for credentials in client-side JavaScript. FulcrumSec’s documented entry route across prior victims is keys exposed in client-side code, repositories and CI/CD logs. Their claimed route here is unconfirmed, but the pattern is theirs.
- Treat attacker volume claims as unverified by default, and say so in your own communications. Never convert gigabytes into people. Nothing supports the arithmetic.
- If you must minimise in public, be certain it is true. This group publishes plaintext specifically to contradict victims who understate.
The position
The interesting question in this story is not whether MAG was late. On the reported timeline it was not. It is which regulator’s clock was even running, and the answer is that only one of the two was, because the other is written in cancelled flights rather than compromised records.
That is a live gap in UK law, and Parliament is in the middle of closing it. Anyone reading this as a Manchester story has the wrong end of it. The next operator in this position, under the Bill as drafted, will owe a notification in 24 hours on facts that today trigger nothing at all.
Sources
- PrimaryMAG statement on cyber security incident, 27 August 2026Manchester Airports Groupaccessed 2026-08-31
- PrimaryData Security Incident, update and FAQsManchester Airportaccessed 2026-08-31
- PrimaryUK GDPR Article 33, notification of a personal data breach to the Commissionerlegislation.gov.ukaccessed 2026-08-31
- PrimaryThe Network and Information Systems Regulations 2018, regulation 11, the duty to notify incidentslegislation.gov.ukaccessed 2026-08-31
- PrimarySI 2018/506 Schedule 2, air transport threshold of 10 million terminal passengerslegislation.gov.ukaccessed 2026-08-31
- PrimaryImplementation of the NIS Directive, DfT guidance v1.1, Annex E aviation thresholdsDepartment for Transportaccessed 2026-08-31
- PrimaryCyber Security and Resilience (Network and Information Systems) Bill, Lords committee stageUK Parliamentaccessed 2026-08-31
- PrimaryLetter to easyJet closing case INV/0250/2020, 17 August 2023Information Commissioner's Officeaccessed 2026-08-31
- PrimaryReporting a cyber security incidentCivil Aviation Authorityaccessed 2026-08-31
- Reported byFulcrumSec claims Manchester Airports hack, theft of 86 GB of data, 30 August 2026BleepingComputeraccessed 2026-08-31
- Reported byManchester, Stansted and East Midlands airports hit by cyber attack, carrying the ICO statementNew Civil Engineeraccessed 2026-08-31


