London Stansted has begun contacting customers after an unauthorised third party accessed personal information held on one of the airport’s systems, a cyber incident that touches several of the services frequent flyers rely on most.
The airport, owned by Manchester Airports Group (MAG), said the compromised records relate to car parking reservations, lounge bookings, Fast Track security purchases and sign-ups to the on-airport WiFi network. The information exposed includes email addresses, phone numbers, vehicle registrations and postcodes.
No payment details in the Stansted Airport data breach
Stansted has stressed that no bank or payment information was involved, because neither MAG nor the system that was accessed stores financial data. That distinction matters, but the personal details that were taken are still valuable to criminals, who can combine them to produce convincing scam messages.
The airport said it took immediate action to secure the affected system and is now working with cyber security specialists and the relevant authorities to establish the scale of the breach and prevent any further access. It said it “takes the security of customer information extremely seriously” and is putting appropriate measures in place to manage the incident.
Stansted has apologised for any concern caused, notified affected customers directly and published further information on the official Stansted Airport website for anyone seeking more detail.
What business travellers should do now
Stansted told customers there is nothing they need to do, but urged particular caution over unexpected emails, calls or text messages claiming to come from the airport. It stressed that it will never ask for payment or banking information out of the blue.
For anyone who uses Stansted regularly, the practical risk is targeted phishing. A criminal holding your email address, phone number, postcode and vehicle registration can send a very plausible message about a parking fine, a booking amendment or a lounge refund. Treat any such message with suspicion, go directly to the airport’s website or app rather than clicking links, and report suspect emails following National Cyber Security Centre guidance on phishing scams.
The inclusion of WiFi sign-up data is a reminder that even free services carry a data cost. Security specialists have long warned about the risks of terminal networks, as we reported in our piece on why experts are wary of free airport WiFi. Where possible, use a VPN or personal hotspot when working airside.
Travel firms are an increasingly popular target
The incident is the latest in a series of attacks on travel infrastructure. Last year Heathrow warned passengers of days of disruption following a cyber-attack on a supplier of check-in systems, while hotel groups have also been hit, with Holiday Inn properties suffering a cyber-attack that affected booking channels.
With millions of travellers now handing personal data to online booking systems, loyalty schemes and airport networks, cyber resilience has become as much a part of operational safety as runway maintenance. For SME travel bookers, the sensible response is procedural rather than panicked. Brief travelling staff on the breach, remind them that airports do not request card details unprompted, and encourage anyone who reused a password on an airport account to change it.
Stansted customers affected by the incident should already have received direct notification. Those who have not heard from the airport but hold parking, lounge, Fast Track or WiFi accounts can check the airport’s website for the latest updates.


