Manchester Airports Group (MAG), which operates Manchester Airport, London Stansted, and East Midlands Airport, confirmed that an unauthorised third party breached its systems and accessed data belonging to approximately 8.7 million customers. MAG said it first learned of the intrusion on Tuesday, August 25, after attackers had been inside the network over the preceding weekend. The exposed data includes information tied to in-airport Wi-Fi sign-ups plus car parking, airport lounge, and Fast Track security bookings: email addresses, phone numbers, vehicle registration plates, and postcodes. MAG says payment card and banking details were not stored on the affected systems, and that airport operations, passenger safety, and aviation security screening were unaffected. According to reporting on the incident, the attackers demanded a ransom, which MAG refused to pay. For security teams, the breach is a reminder that public-facing convenience systems bolted onto critical infrastructure, such as guest Wi-Fi portals, paid parking reservations, and lounge booking widgets, are frequently built and maintained by third-party vendors with weaker security postures than the core operational technology they sit next to, and they still carry enough personal data to fuel large-scale, highly convincing phishing and smishing campaigns impersonating the airport or an airline. Because vehicle plate and postcode data can be cross-referenced with other leaked datasets, affected travelers face elevated risk of targeted scams referencing real upcoming trips, and organizations running similar ancillary customer-facing booking systems should treat this incident as a prompt to audit which third-party integrations can reach sensitive customer PII and whether that access is properly segmented from booking convenience features.