Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Hackers Hit Manchester, Stansted and East Midlands Airports, Access Data on 8.7 Million Customers

Manchester Airports Group confirmed Thursday that hackers broke into systems tied to three of England's busiest airports, accessing personal data belonging to roughly 8.7 million customers.
The affected airports are Manchester Airport, London Stansted and East Midlands Airport, all owned by MAG. Together they handled more than 65 million passengers over the past year, according to The Record.
MAG says it first learned of the breach on Tuesday, August 25, but believes the hackers actually got in a few days earlier. The company has not disclosed how the attackers gained access or what else they may have done inside the system beyond pulling customer data, according to The Record.
What got stolen
The compromised data covers email addresses, phone numbers, vehicle registration numbers and postcodes. MAG says this information came from customers who signed up for in-terminal WiFi, booked car parking, reserved airport lounges, or used fast-track security lanes.
A company spokesperson told The Register and The Yorkshire Post that the "vast majority" of the 8.7 million affected customers only had their email address exposed. The more sensitive data, like vehicle registrations, came from a smaller pool of people who paid for parking, lounge access or fast-track service.
MAG has been consistent across every outlet on one point: no bank or payment card details were stored in the compromised system, so none were taken.
What MAG is saying, and what it isn't
MAG's public statement, quoted nearly word-for-word by the BBC, The Guardian, The Independent, the Daily Star and the Daily Mirror, says the company "immediately contained the risk" after discovering the intrusion, brought in outside cybersecurity specialists, and notified "the relevant authorities."
BBC reported that MAG said it knows the identity of the hackers and has passed that along to authorities. No agency has announced charges, and no law enforcement body has been named as confirming an active investigation in the statements provided.
The company insists passenger safety and aviation security were never at risk, and that flights, terminal operations and parking continue running normally. That claim hasn't been contradicted by any source.
As a precaution, MAG temporarily suspended its Manage My Booking online service. Customers with a booking due to change within 72 hours of the announcement are being told to call customer service instead of using the site. MAG says all existing reservations remain valid and most customers don't need to do anything.
The gap in the reporting
None of the seven outlets pin down exactly how many days elapsed between the initial breach and MAG's discovery of it, beyond "a few days," per the Daily Star and Daily Mirror, both citing the Manchester Evening News. A longer undetected dwell time generally means more opportunity for data to be copied, sold or exploited before a company even knows to react.
The Register also flagged something for anyone still frustrated: airport parking already isn't cheap, and getting a breach notification on top of an £80 five-day parking bill, as one reader told the outlet, is salt in the wound. That's a fair complaint about airport pricing generally, though unrelated to the security failure itself but part of the public reaction.
What customers should actually do
Every outlet carries the same warning from MAG: watch for phishing attempts. The company says it will never contact customers out of the blue asking for banking details, passwords or payment information. Anyone who gets a call, text or email demanding that kind of information and claiming to be MAG should treat it as fraudulent.
MAG has already emailed affected customers directly with breach notifications, according to The Independent and the Daily Mirror.
What's unresolved
MAG hasn't said which regulator, if any, it has formally notified under UK data protection law, nor has the Information Commissioner's Office issued a public statement on this incident in the material available. It also hasn't disclosed the identity of the attackers publicly, despite BBC's report that the company knows who they are. Whether this breach draws a formal ICO investigation, and whether MAG faces any penalty under UK GDPR for the incident, remains an open question with no timeline attached.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.