spear-phishing data breach

8.7 Million Airport Customers Had Their Data Stolen. Were You One of Them?

In August 2026, Manchester Airports Group (MAG) announced a cyberattack affecting approximately 8.7M customers. The company owns Manchester, London Stansted, and East Midlands airports.

The attackers did not get customers’ banking or payment information. Instead, the stolen information included things like email addresses, phone numbers, postal codes, and vehicle registration numbers associated with airport parking, lounge and Fast Track bookings, and Wi-Fi registrations.

At first glance, that might sound like relatively harmless information. Unfortunately, cybercriminals don’t always need your credit card number to cause problems.

Imagine receiving a text message a few weeks after returning from vacation:

“Manchester Airport Parking: We noticed an issue with your recent parking payment. Please verify your vehicle registration and payment information.”

In this scenario, you actually did use airport parking recently. In fact, the message knows which airport you visited. It might even know your vehicle registration and other personal information.

Suddenly, that message seems a lot more believable. In fact, this demonstrates one of the biggest risks that come after a data breach. Cyber-criminals can use legitimate information about you to make their targeted attacks much harder for victims to recognize.

Generic phishing attacks cast a wide net. For instance, you’ve probably received obviously fake emails claiming that your Netflix account was suspended when you don’t even have a Netflix account.

Spear-phishing works much differently.

Instead of sending the same message to thousands of random people, bad actors use information they already know about you to make their message more convincing. An attacker who knows your name, phone number, email address, postal code, and a company you’ve recently patronized can make you believe that you’re speaking with a legitimate representative.

By doing this, threat actors can impersonate that company and ask you to reset your password, confirm a payment, or provide additional information. That first batch of stolen information then becomes bait for stealing much more valuable account information.

Unfortunately, your information likely exists in more than one stolen database. That complicates the situation. One breach might expose your email address and phone number, while another leaks an old password, and a third reveals your date of birth or home address.

Cybercriminals can combine information from different sources to create a much more complete picture of you.

This is why seemingly minor breaches still matter.

An email address might not seem particularly sensitive on its own, but combine it with your phone number, location, purchase history, and a password you reused somewhere else, and the situation changes quickly.

If a company tells you that your information was exposed, pay attention to exactly what was reportedly stolen. Then think about how someone could use that information against you.

A few, simple precautions can help.

  • Unexpected messages claiming to come from the breached company should raise suspicion.
  • Never provide passwords or security codes to someone who contacted you unexpectedly.
  • Use password managers to protect your sensitive accounts.
  • Go directly to the company’s website instead of clicking links in emails or text messages.
  • Change any exposed passwords, especially if you reused them elsewhere.
  • Enable multi-factor authentication or passkeys whenever possible.
  • Watch your accounts for unusual login attempts.

Most importantly, expect spear-phishing attempts after a breach. The attacker may already know enough about you to sound real.

Stolen data doesn’t need to include your credit card number to create a cybersecurity risk, as the breach on Manchester Airports Group illustrates. Sometimes criminals steal basic information first and then use it to convince you to provide the sensitive information they actually want. That means the email or text you receive after a breach may know surprisingly specific details about you. You still can’t assume that makes it legitimate.

When an unexpected message asks you to click, pay, log in, or provide additional information, you should always verify the request another way first.

The scammer may know who you are, but that doesn’t mean you have to give them any private information.

Related Posts