NordVPN Promotion

Home / News

FulcrumSec Claims 86 GB Data Theft in Manchester Airports Breach

Manchester Airport tower overlooks operations amid scrutiny of data breach. (Photo: Manchester Airports Group)

An extortion group calling itself FulcrumSec has claimed responsibility for the cyberattack on Manchester Airports Group (MAG), saying it stole 86 GB of data and obtained more detailed customer and travel information than the airport operator initially disclosed.

MAG confirmed on August 27 that an unauthorized third party had obtained customer data associated with Manchester, London Stansted and East Midlands airports. The operator said the affected systems contained information from airport Wi-Fi registrations and car park, lounge and Fast Track bookings, including email addresses, phone numbers, vehicle registrations and postcodes. MAG said bank and payment details were not held in the affected system and that airport operations and aviation security were unaffected.

Samples supplied by FulcrumSec indicate a broader set of exposed information. BleepingComputer said it authenticated one record against a traveler’s known Manchester Airport purchase history. Samples included booking and purchase references, products purchased, prices, parking dates and times, IP addresses, approximate locations, device information and historical spending. The publication said it saw no payment-card or bank-account information.

FulcrumSec also supplied roughly 21.5 GB Manchester customer export containing consolidated customer profiles, booking histories and marketing classifications. The group claims the overall theft amounted to 86 GB and included nearly 200,000 records concerning travel scheduled during the remainder of 2026. BleepingComputer said it could not independently establish the total amount stolen or verify the claim about upcoming-travel records.

The group says exposed API credentials provided its route into the data. FulcrumSec told BleepingComputer that it used airport-specific credentials for Iterable, a customer-engagement platform, that were exposed in client-side JavaScript. MAG has not confirmed that account of the intrusion. Asked about the 86 GB figure, exposed credentials and future-travel records, the company declined to address those claims specifically.

MAG has said about 8.7 million customers were affected, with only email addresses exposed for the “vast majority.” The company says it has contacted affected customers, including those with upcoming bookings.

The additional booking and travel details could make targeted fraud more convincing. Information tying an individual to a particular airport, vehicle, parking period or purchased service could be incorporated into phishing emails, text messages or calls. MAG has advised customers to be alert to suspicious communications and says it will not unexpectedly request payment-card details, banking information or passwords.

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By CircleID Reporter

CircleID’s internal staff reporting on news tips and developing stories. Do you have information the professional Internet community should be aware of? Contact us.

Visit Page

Filed Under

Comments

Comment Title:

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

Brand Protection

Sponsored byCSC

New TLDs

Sponsored byRadix

Cybersecurity

Sponsored byVerisign

IPv4 Markets

Sponsored byIPv4.Global

DNS Security

Sponsored byWhoisXML API

DNS

Sponsored byDNIB.com

Domain Names

Sponsored byVerisign

NordVPN Promotion