Marketing Built the Breach Surface at Three Airports
Manchester Airports Group lost email addresses, phone numbers, vehicle registrations and postcodes. Every one of them was collected by a growth team, from a car park booking, a lounge upgrade or a wifi sign-up.
By Katie Delaney · 2026-08-29 · 14 min read
What was taken, and where it was collected#
Nobody breached the flight operations system. They breached the car park booking, the lounge upgrade and the wifi sign-up, which is to say they breached marketing.
On 27 August 2026, Manchester Airports Group published a notice confirming what it called a cyber security incident by an unauthorised third party. The notice on its Stansted site is short, and the specific list in it is the reason this story belongs to marketing rather than to infrastructure.
The data taken was "customers' email addresses, phone numbers, vehicle registrations and postcodes". The systems it came from were car park bookings, lounge and Fast Track bookings, and airport wifi sign-ups, across Manchester, Stansted and East Midlands. MAG also states that "Neither MAG nor the system accessed hold customers' bank or payment details".
Every one of those is a marketing capture point, not a runway#
Read the list again as a marketer rather than as a security analyst. A car park booking is a conversion. A lounge upgrade is an ancillary revenue product. A wifi sign-up is a permission grab, the classic exchange of an email address for twenty minutes of connectivity. Not one of them is an operational system. All four are places where a growth team asked a customer for something.
That is the whole customer data protection lesson of this incident, and it will be missed by most of the coverage. The attacker did not need to reach anything that flies aeroplanes. They reached the part of the business whose job is to collect identifiers, and identifiers were exactly what they took.
On the number of people affected, be careful. MAG's own notice states no figure at all. The widely repeated 8.7 million comes from trade and security press on 28 August, including Help Net Security which says only that "UK outlets have reported around 8.7 million customers were caught up in the breach", and The Record. Treat it as reported and unconfirmed, because MAG has confirmed nothing of the kind.
The distinction is not pedantry. It decides who owns the fix. If the failure sits in an operational system, it belongs to engineering and it gets an engineering budget. If it sits in a booking funnel and a wifi splash page, customer data protection becomes a marketing responsibility, and marketing is rarely resourced or asked to carry it. Coverage of the incident has mostly treated it as a security story, which is how the actual lesson gets missed.
Ask the uncomfortable question about your own estate before somebody else does. If an attacker reached only your marketing systems and nothing else, what would they walk away with? For most organisations the honest answer is a near-complete customer list with contact details, location and behavioural history attached, which is to say the most saleable thing the company owns.
The regulator's own data says this is ordinary#
It is tempting to file this as an unlucky one-off. The regulator's own data says otherwise, and says it loudly enough that any customer data protection conversation should start there instead.
The Information Commissioner's Office publishes every personal data breach reported to it, quarter by quarter, as a data security incident trends dataset. We downloaded the full release covering Q1 2019 to Q4 2025 and counted it ourselves. The ICO warns that a single report appears on several rows when it carries several characteristics, so we counted distinct incidents by reference, year and quarter rather than counting rows. For calendar year 2025 that gives 13,457 distinct incidents.
Three quarters of reported breaches in the United Kingdom last year were not hacking at all. The single most common incident type was data emailed to the wrong recipient, at 18.3 per cent of incidents, ahead of unauthorised access at 11.9 per cent and phishing at 11.3 per cent. Failure to redact accounted for 6.6 per cent on its own.
That matters for where a customer data protection budget goes. A great deal of it goes to the 23 per cent, and comparatively little to the process, permission and handling questions that produce the other 77 per cent. Marketing operations sits squarely in that larger, quieter share.
Customer data protection fails where marketing collects#
Basic personal identifiers appear in 80.6 per cent of 2025 incidents. That category is precisely what MAG lost: names, emails, phone numbers, postcodes, the unglamorous middle of every customer relationship management system in the country. Health data appears in 28.0 per cent and economic or financial data in 15.4 per cent.
Two caveats on our own numbers, because a statistic without its method is just a rumour with a decimal point. First, the shares in these charts exceed 100 per cent because one reported incident can carry several data types and several categories of affected person. Second, the ICO publishes reports made to it, so this is a picture of reported breaches, not of all breaches. Both caveats push in the same direction: the real customer data protection picture is larger, not smaller. The dataset itself is published openly if you want to check our arithmetic.
Put crudely: if you spend on customer data protection in proportion to where breaches actually happen, roughly three quarters of the budget belongs to process, permission and handling, and roughly a quarter to defending the perimeter. Almost nobody splits it that way.
Whose data is actually in a breach#
So who are these breaches actually about? We counted that too, and the answer reframes the whole customer data security conversation.
Customers and prospective customers are the largest single group, present in 32.1 per cent of incidents. Note the phrase includes prospective customers. People who never bought anything, whose details were captured against a future sale that never happened, are inside a third of the country's reported breaches.
This is the part that should change behaviour. A prospect record has no revenue attached and full liability attached. It is the worst trade in the entire customer data protection ledger, and marketing creates it by default, in bulk, every time a form goes live without an expiry policy.
Wifi portals are the sharpest example, and there is real research on them. Ali, Osman, Mannan and Youssef analysed 67 public wifi hotspots in Montreal across restaurants, parks, coffee shops, shopping malls, trains, airports, hotels and libraries. They documented the "collection of a significant amount of privacy-sensitive personal data through the use of social login and registration forms", and found that most hotspots set persistent third-party tracking cookies inside the portal itself. Those cookies, the authors note, can keep following a person's browsing long after they have left the building, in some cases for as long as twenty years.
Twenty years, for twenty minutes of connectivity, collected by a growth team, and now a customer data protection liability sitting on somebody's balance sheet.
It is worth sitting with the prospect number for a moment longer. Every growth team in the country is measured on the size of its database, and nobody is measured on its decay. So the pile grows, quarter after quarter, long after the campaign that justified it has been forgotten. Customer data security is mostly the discipline of throwing things away, and no dashboard anywhere rewards it.
The undisclosed half of the problem is worse still, and somebody measured it two days ago. A practitioner posting in r/gdpr scanned 458 recent Product Hunt launches from an EU location and checked what each site actually loaded against what its privacy policy admitted to. The gap was large enough to be the finding.
60% of sites load with a foreign vendor that their privacy policy doesn't mention. Google Analytics, Google Ads and Posthog are the top 3, most common (and commonly unmentioned) ones.
Read that as a customer data protection finding rather than a compliance one. Three in five sites were sending data to a third party the business had not declared, and the top three culprits are the ordinary furniture of a marketing stack. Nobody chose this. It accumulated, one tag at a time, exactly the way the MAG capture points accumulated.
Two honest caveats on that scan, because we would want them applied to our own numbers. The author runs a legal documentation tool, so has a commercial interest in the answer, and the privacy policies were assessed with a language model rather than by a lawyer. The direction is credible and the precision should be held loosely, which is true of most things in this field.
What you owe, and how fast#
The obligations are not vague and they do not wait for the investigation to finish.
Data breach notification is a communications job with a legal deadline#
The 72-hour clock is a data breach response problem long before it is a legal one, because the organisation has to decide what it knows while it still barely knows anything. MAG's notice threads that needle reasonably well: it says what was taken, names the systems, states plainly that payment details were not held, and says it has "informed and are working with the relevant authorities" without naming them.
Compare that with a very different approach the same week. McKesson filed an 8-K with the Securities and Exchange Commission disclosing a cybersecurity incident discovered on 25 August, and filed it under Item 7.01, the voluntary Regulation FD disclosure item, rather than Item 1.05, which covers material cybersecurity incidents. The filing states the company "has not determined that the incident is material". Claims about the scale of that incident, reported by BleepingComputer, come from the attackers rather than the company.
Two disclosures, two registers, one week. One names the data and the systems. The other names the item number under which it would rather not commit. Both are defensible. Only one reads as though it was written for customers.
Data breach notification also has a second audience nobody drafts for, which is every other customer you have. A notice written only for the affected group still gets read by journalists, competitors and regulators, and it is the clearest signal you will ever send about how seriously you take customer data protection. MAG's notice is plain and specific, and plainness reads as competence in a way that legal hedging never does.
Five fixes that look like deletion#
The practical work here is not a security project. It is a retention project, and marketing owns it.
Wifi portals, competition entries, gated downloads, booking flows, ancillary upsells, abandoned carts. Anywhere a form takes an identifier.
For every field, name the campaign or process that uses it. Fields with no named use are pure liability and should stop being collected today.
Give unconverted prospect records a deletion date and enforce it automatically. This is the single largest reduction available in most estates.
Wifi and booking portals frequently carry tracking set by a supplier, not by you. Enumerate them and set your own cookie lifetimes.
Draft the holding notice now, decide who signs it, and agree what you will say before you know everything. The clock starts at awareness, not at certainty.
Run it as a quarterly prowl rather than a one-off project. New forms appear constantly, usually attached to a campaign that needed to ship on a Thursday, and a customer data protection audit six months old is describing a database that no longer exists. Put it in the calendar next to the reporting cycle and it takes an afternoon. Leave it and it becomes an incident.
None of that requires a new platform. It requires somebody senior enough to say no to a field on a form, which is a different and rarer sort of authority. Most customer data protection failures we see in regulated categories are not technical at all, they are the accumulated result of nobody ever removing anything.
There is a commercial argument as well as a compliance one, and it is the one that actually moves budgets. A smaller, cleaner, permissioned database performs better. Deliverability improves, segmentation gets sharper, and the paid social audiences you build from it match more reliably because the records that remain are the records that are real.
The industry mood is shifting in the same direction. More than 150 technology and security firms (we counted 155 on OpenAI's own signatory list on 29 August, against the "nearly 130" reported at publication) signed a collective cyber defence pledge this week, and regulators are increasingly interested in what marketers claim their data can do: the FTC finalised orders against Cox Media Group and two partners over an advertising product sold as listening through smart devices. Collection, claims and consequences are converging.
The fox in the hedgerow does not test the fence where it is strongest. It walks the whole line until it finds the gap somebody left open, and in most organisations that gap is a form nobody has looked at since 2021. Personal data breach exposure follows the same logic, which is why the sharpest customer data security work this year will look like deletion rather than defence.
Read the MAG notice, then go and read your own wifi terms. If the second document is longer than the first and nobody in the building can say what it collects, you have found this week's job. Our brand strategy work starts in the same unfashionable place, because trust is mostly the sum of things a company chose not to take. If you want a hand with that audit, talk to us.
If your organisation runs an app as well as a website, extend the same sweep there, because mobile SDKs collect on a different trail and are frequently forgotten in a customer data protection review. The same applies to any gated content programme that has been quietly harvesting details for years against a nurture sequence nobody has run since 2023.
The scent to follow is always the same one. Find the form, find the field, find the retention rule, and ask who would miss it. Customer data protection done properly is unspectacular and slightly boring, and it is the only version that survives contact with an actual personal data breach at two in the morning.
Frequently asked questions#
What is customer data protection?
It is the set of practices that keep customer personal data safe, lawful and no larger than it needs to be. In practice it covers what you collect, why you collect it, how long you keep it, who can reach it, and what you do when something goes wrong. Most of it is process rather than technology.
How long do we have to report a personal data breach in the UK?
The ICO says organisations must report to it within 72 hours of becoming aware of the breach, where feasible, under Article 33 of the UK GDPR. Where the breach is likely to result in a high risk to individuals, those individuals must also be told without undue delay.
How do you protect customer data privacy in marketing?
Collect fewer fields, name the use for each one, set an expiry date on unconverted prospect records and enforce it, audit the third-party tracking on any portal or booking flow, and keep a record of every breach whether or not it was reportable.
Are most data breaches caused by hackers?
No. Our count of the ICO's published dataset found 76.6% of the 13,457 distinct UK incidents reported in 2025 were categorised non-cyber. The single commonest type was data emailed to the wrong recipient at 18.3%, ahead of unauthorised access and phishing.
What should a data breach response plan contain?
A named decision maker, a pre-drafted holding notice, an agreed threshold for telling individuals, a contact route to the regulator, and a rehearsed sequence. The point is deciding in advance what you will say while you still know very little, because the 72-hour clock starts at awareness.
Is wifi sign-up data really a risk?
Yes. Research on 67 public wifi hotspots documented significant collection of personal data through social login and registration forms, plus persistent third-party tracking cookies set inside the portal that can follow browsing for as long as twenty years after the visit.
Read more on this topic#
Third-Party Risk Management After the PTC Windchill Breach
When the gap in the fence belongs to somebody else entirely.
Read the pieceAny Best Healthcare Marketing Agency Now Has Six Pixel Laws to Check
The same argument, in the category with the least room for error.
Read the pieceCISA Tested Two SOCs. Only One Had an Incident Response Plan That Held.
What rehearsal actually buys you when the clock starts.
Read the pieceAutomated Penetration Testing Stopped Four Short
The other August number worth reading before you buy the automation.
Read the pieceNot sure what your forms are actually collecting?
folkfox audits the marketing side of the data estate: every capture point, every field, every retention rule, and the notice you would have to send at three in the morning. Unfashionable work that quietly removes most of the risk.