The Manchester Airports Group Breach Was Larger Than Reported. Much Larger.

Initial reports focused on 8.8 million users. DataBreach.com found 273,558,352 unique email addresses in the leaked files - suggesting the true number of people affected is vastly higher.
When news of the Manchester Airports Group (MAG) breach broke, a single metric anchored the headlines: 8.8 million unique emails.
That number was not necessarily wrong. It was simply incomplete.
A deep-dive analysis of the leaked archives by DataBreach.com reveals an operational footprint that extends far beyond the main customer rosters initially counted. After extracting every email address across the raw dataset and removing all duplicates, our index settled on 273,558,352 unique addresses.
That represents a 31-fold jump over the widely accepted figure.
To be clear, unique email addresses do not map 1:1 to unique individuals. A single person might use multiple inboxes, while other addresses in the database may be dormant, automated, or invalid. But even after accounting for those operational redundancies, the telemetry strongly indicates the breach touched hundreds of millions of people - not just the 8.8 million cited in initial disclosures.
The 8.8 million figure only described the address book
According to MAG's public disclosures, the stolen records originated from parking, lounge, and Fast Track reservations, as well as airport Wi-Fi captive portals across Manchester, London Stansted, and East Midlands airports.
The exposed data included email addresses, phone numbers, vehicle registration plates, and postcodes. MAG confirmed that financial details were not stored within the affected system. Read MAG’s breach notice.
When DataBreach.com parsed the dump, the core user tables reflected those original totals with precision:
- 4.38 million profiles in Manchester’s user file
- 3.52 million profiles in Stansted’s user file
- 755,000 profiles in East Midlands’ user file
Combined, these account for roughly 8.66 million profiles - nearly an exact match for the official narrative.
In MAG’s infrastructure, however, a "user profile" merely represents a stored contact record. Someone became one by connecting to airport Wi-Fi, booking parking, purchasing Fast Track access, or subscribing to email updates. It did not require creating a password-protected account or booking a flight.
If those user tables served as MAG’s corporate address book, the remainder of the leak was its detailed operational diary - and that diary captured a significantly wider audience.
Where the other email addresses appeared
Beyond the primary user rosters, the archives contained massive event logs generated whenever MAG’s backend dispatched an email, logged an open rate, processed an opt-in, registered an unsubscribe request, or recorded a purchase.
Our extraction isolated:
- 43.8 million unique email addresses in Stansted’s
events_emailSendfile; - 35.8 million in Manchester’s equivalent log; and
- 34.9 million in the East Midlands log.
Those email-dispatch files alone contained roughly 114.5 million email entries. Millions more were spread across subscription records, open tracking files, unsubscribe logs, and purchase receipts.
Typically, event logs are inflated by heavy repetition - a single passenger receiving 20 travel updates generates 20 separate log rows. But DataBreach.com did not reach 273,558,352 by simply totaling raw database rows. We extracted the actual email strings and deduplicated them across the entire dataset.
The result was 273,558,352 distinct, non-duplicate addresses.
This raises a critical question for security teams: Why did systems built around roughly 8.8 million active customer profiles hold over 273 million distinct email records?
The raw data reveals where these addresses sat, but not why they were retained or whether every address belonged to an active customer. The total likely blends historical contacts, imported marketing lists, legacy accounts, automated system handles, and third-party integrations not accounted for in primary user metrics.
MAG should clarify the origin of this massive address pool and confirm whether the people behind those addresses will receive formal notice.
Much larger than initially understood
The 8.8 million figure accurately describes the static profiles sitting in MAG's primary contact tables. It fails entirely to reflect the true volume of unique identities scattered across the rest of the compromised environment.
DataBreach.com confirmed 273,558,352 unique email addresses after deduplicating the entire leak. While that figure doesn't mean 273.5 million distinct individuals were impacted, it proves the original 8.8-million frame was far too narrow.
The true human toll sits somewhere below the unique email count. Yet given the scale of the gap, the real number of affected individuals likely reaches into the hundreds of millions.
The Manchester Airports Group breach was larger than first reported - potentially much larger.















