Blog · 27 August 2026

“No bank details were accessed” is not the reassurance it sounds like

A driver viewing a suspicious airport parking payment message beside a car with a fictional registration plate

What the Manchester Airport breach tells every business in Greater Manchester

If you have parked at Manchester Airport, used a lounge, booked Fast Track or joined the on-airport WiFi, there is a reasonable chance an email from Manchester Airports Group landed in your inbox this week.

The message is calm, well written and does most things right. It confirms an incident. It names the systems involved. It states clearly that no bank or payment details were held in the system accessed. It urges customers to be wary of unexpected contact claiming to be from the airport.

And then it says something that deserves a second look: "There is no action you need to take."

For the average customer, that is broadly fair. For anyone who runs a business, it is the opposite of true. There is a great deal to take from this, and almost none of it is about airports.

What was actually taken

According to the notification, the data accessed by an unauthorised third party includes:

  • Email addresses
  • Phone numbers
  • Vehicle registrations
  • Postcodes

No card numbers. No bank details. No passwords, as far as the notification goes.

On a risk register, that scores low. Reputationally, it reads as a near miss. In the hands of someone building a phishing campaign, it is close to a perfect starting hand.

The scam that writes itself

Think about what a criminal can now construct.

They have your email address. They have your mobile number. They know roughly where you live. And they know your car’s registration plate, tied to a confirmed fact: you were at Manchester Airport.

Now picture the text message.

Manchester Airport: an unpaid parking charge has been recorded for vehicle [YOUR ACTUAL REG]. Pay £4.20 within 48 hours to avoid a £100 penalty.

Every scam warning we give people falls apart against that message. We tell them to look for generic greetings, but this one is specific. We tell them to be suspicious of details the sender should not know, but the sender knows their number plate. We tell them to check whether the story is plausible, and this story is not just plausible, it is confirmed by their own memory of parking there.

Vehicle registrations are rarely exposed in breaches, and that is exactly why they are so effective. A reg plate is a credibility token. It converts a mass phishing campaign into something that feels personally addressed, and it does it at scale, automatically, across every record in the file.

Postcode and phone number then do the rest. Fake parking charge notices, fake DVLA fine texts, fake refund calls, fake "your booking has been cancelled" emails. The pretexts are cheap and the conversion rate on this data set will be significantly above average.

So no, the payment data was not stolen. It will simply be requested directly from the customer instead, and many will hand it over.

If you received the email

Three things, and none of them require panic.

  1. Treat every parking, fine, refund or booking message about Manchester Airport as hostile for the next several months. Not just this week. Stolen data gets resold and reused long after the news cycle ends.
  2. Never pay or verify anything through a link in a message. Go to the organisation’s website directly, or use the number on your original booking confirmation.
  3. Tell the people around you who are more likely to be caught. Parents, grandparents, anyone who would rather pay £4.20 than risk a £100 fine. That instinct is precisely what the scam is engineered to exploit.

Now the part that matters if you run a business

Look again at which systems were involved. Car parking. Lounge bookings. Fast Track. WiFi sign-ups.

Not the flight operations network. Not the finance system. Not the core platform anyone would have listed as critical. The incident sits in the customer-facing periphery, in the systems that collect information from the public because collecting it was convenient at the time.

Every organisation has these. Ours included. Yours certainly does.

The booking form nobody owns. The enquiry form that emails a shared inbox and quietly writes to a database. The events sign-up from 2021. The recruitment portal. The customer portal that a developer built, invoiced for, and never touched again.

Guest WiFi. If you run a captive portal that asks visitors for a name, an email and a mobile number before they can connect, you are running a marketing database. Ask yourself who administers it, where the data sits, how long it retains records, and when it was last patched. For most SMEs the honest answer to at least three of those is "I don’t know."

Data you no longer need. The single most effective control against a breach of this type is not a firewall. It is not holding the data in the first place. If a record has no operational purpose, it is not an asset, it is a liability sitting on a shelf waiting to appear in a notification email. Retention schedules are unglamorous and they are one of the highest return security investments available to a small business.

Third parties. Peripheral systems are very often supplier-operated. That does not transfer the responsibility. Under UK GDPR you remain the data controller for information you collect, whatever your supplier’s contract says. If you cannot name the processor behind each of your customer-facing forms, that is the gap.

The uncomfortable question

Here is the test we put to clients, and it takes about ten seconds to fail.

Write down every system in your organisation that holds personal data about customers, patients, residents, service users, applicants or the general public. Not the obvious three. All of them.

Then, for each one, name the person responsible, the supplier, the retention period and the date of the last security review.

If you run a care service, add one more column: which of these would you have to explain to the ICO, to your local authority commissioners, and to families, in the same week.

Most organisations get four or five entries into that list and realise they are guessing. That is not a failure of diligence. It is what happens when systems accumulate over a decade of doing business. But it is also exactly how a breach ends up living in a car park booking system rather than anywhere anyone was watching.

Credit where it is due

MAG’s notification is, in fairness, a reasonable piece of incident communication. It is prompt, specific about the data categories, honest about the unauthorised access, and it explicitly warns customers about follow-on phishing. Plenty of organisations facing the same situation have done far worse, far more slowly.

The lesson is not that a large organisation was careless. It is that a well-resourced business with a serious security function still had personal data taken from a peripheral customer system.

If that can happen there, the question is not whether it could happen to your business. It is whether you would know.


BM Technologies is a managed IT and cyber security provider based in Milnrow, Rochdale, working with businesses and care providers across Greater Manchester and the North West.

Want to know how exposed you actually are? Our free cyber risk assessment takes a few minutes and gives you a plain English score with the specific gaps that need attention: ratemycyber.co.uk

Tech That Works.

← Back to all articles

Want to talk through anything in this article? Contact us and we’ll help.

Reviews

Testimonials