OptMsg Breach Breakdown: Manchester Airports

Manchester Airports Data Breach: 8.8 Million Travellers, What It Means for You

Claire booked a week in Manchester Airport’s long-stay car park for the October half-term back in June. She typed in her email, her mobile number, her postcode and her number plate, and thought nothing more of it. That one form is now in a file anyone can download: her address area, the car that will be gone from her drive, and the dates the house is empty.

Confirmation: confirmed by the company. Manchester Airports Group published a statement on 27 August 2026; the 8.8 million figure comes from Have I Been Pwned’s load of the leaked data, not from MAG.

What happened

On 27 August 2026, Manchester Airports Group (MAG) — the operator of Manchester, London Stansted and East Midlands airports — confirmed that an unauthorised third party had taken customer data from its car park, lounge, Fast Track and in-airport Wi-Fi systems. MAG’s statement and FAQ says the incident was contained, the authorities were told, and airport operations were not affected.

The extortion group FulcrumSec claimed the attack the same week. BleepingComputer reported the group’s claim of 86 GB of data, and its account of how it got in: admin keys for Iterable, the marketing platform MAG used, sitting in the JavaScript of the three airport websites. That access story is the attacker’s claim; MAG has not confirmed it.

MAG did not pay. In early September, SecurityWeek reported that FulcrumSec had published the data on its leak site. On 2 September, Have I Been Pwned loaded the leaked file and verified 8,849,657 unique email addresses.

The count is not settled. MAG has not published a number. Early press reports put it at 8.7 million; Have I Been Pwned’s count is 8.85 million; FulcrumSec claims its export runs to hundreds of gigabytes uncompressed and includes about 191,000 future bookings. Treat the HIBP figure as the one verified independently.

What was exposed

MAG says the stolen data includes email addresses, phone numbers, vehicle registrations and postcodes, and that no bank or payment details were held in the system. Have I Been Pwned’s load adds names, IP addresses, browser details, geographic locations and purchase records.

Here is what each item is worth to a criminal:

  • Email address plus the fact you used Manchester, Stansted or East Midlands. That is enough to write a convincing “your parking booking has a problem” message. Expect it.
  • Mobile number. Same message, by text — a smishing wave dressed as the airport, a parking operator or a lounge.
  • Number plate and postcode together. A car that can be looked up, and roughly where it lives. Combined with a future booking, it is also a window when nobody is home.
  • Purchase and booking history. Real details from your real booking make a fake email look right. A scam that quotes your actual parking dates is far harder to spot than a generic one.

Nothing in this breach is a password. That matters below.

What to do now

The practical risk from this breach is the follow-up: a message that looks like the airport, quotes your real booking, and asks you to click. Most of what protects you here has nothing to do with OptMsg.

1. Check your address at Have I Been Pwned. If it is in the Manchester Airports Group load, assume every item above is out. 2. Treat any airport, parking or lounge email or text as suspicious for the next few months. Do not click links in them. Go to the airport’s website directly, or open the app, and check your booking there. MAG says it will not contact customers out of the blue asking for card details, bank details or passwords. 3. Do not reuse a password across sites. No password leaked here, but a criminal holding your email will try it against every site where a password did leak. A password manager makes unique passwords painless. 4. Turn on the strongest sign-in each account offers — a passkey where available, an authenticator app otherwise — starting with your email account, because it is the reset route into everything else. 5. If a booking is coming up, MAG’s FAQ says you can change or cancel it at no charge and it will be refunded. If your plate and travel dates are in the leak and that worries you, that is the lever. 6. Watch the physical side. If your plate, postcode and a travel window are all out, tell a neighbour, and do not post your trip on social media until you are back.

How OptMsg changes this exposure

Honestly, and at its real size: OptMsg would not have prevented this breach. It happened at MAG, in MAG’s systems. What an opt-in inbox changes is what happens to you afterwards.

Mail from a sender you have not approved goes to Trash, not your Inbox, and auto-deletes after 30 days. OptMsg’s patent-pending opt-in technology means the fake “parking booking problem” email lands in Trash, where you are not reading it under time pressure; the airport itself reaches your Inbox only if you approved it as a sender. Only people you approve can reach your inbox. Everyone else goes to Trash.

Then the password point. Your OptMsg account has no password, so a password stolen from another site can’t open your inbox. When a criminal takes an email address from this leak and pairs it with a password from some other breach, the pair opens nothing at OptMsg — there is no password on the account to match.

What that does not cover: a text message to your phone, a phishing page you open yourself, or someone with your unlocked phone. The airport smishing wave is the part you still have to handle with the steps above.

If you want the next breach’s follow-up mail to land in Trash instead of in front of you, see how Simple by Design works, or read what opt-in email is and how it shields your inbox.

Ready for an inbox that stays quiet after a breach? Create Your Account.

Your Inbox. Your Rules.

Frequently asked questions

Was my payment card exposed in the Manchester Airports breach? MAG says no. Its statement says neither MAG nor the affected system held customers’ bank or payment details. The exposed data is email addresses, phone numbers, vehicle registrations and postcodes, with names, purchase records and IP data in the leaked file.

How do I know if I am affected? MAG says it has contacted affected customers directly. You can also search your email address at Have I Been Pwned, which loaded the leaked data on 2 September 2026 with 8,849,657 unique addresses.

Is my upcoming parking or lounge booking still valid? Yes. MAG’s FAQ says upcoming bookings are unaffected and no action is needed. If you want to change or cancel because of the incident, MAG says it will do so at no charge with a full refund.

Did the breach leak passwords? No password is listed in MAG’s statement or in the Have I Been Pwned data classes. The risk is phishing and smishing that uses your real booking details, and criminals pairing your email with passwords leaked elsewhere.

Would OptMsg have stopped this? No. The breach happened at MAG. What OptMsg changes is the aftermath: unapproved senders go to Trash rather than your Inbox, and there is no password on an OptMsg account for a leaked credential to match.

Sources

Scroll to Top