|
||

An extortion group calling itself FulcrumSec has claimed responsibility for the cyberattack on Manchester Airports Group (MAG), saying it stole 86 GB of data and obtained more detailed customer and travel information than the airport operator initially disclosed.
MAG confirmed on August 27 that an unauthorized third party had obtained customer data associated with Manchester, London Stansted and East Midlands airports. The operator said the affected systems contained information from airport Wi-Fi registrations and car park, lounge and Fast Track bookings, including email addresses, phone numbers, vehicle registrations and postcodes. MAG said bank and payment details were not held in the affected system and that airport operations and aviation security were unaffected.
Samples supplied by FulcrumSec indicate a broader set of exposed information. BleepingComputer said it authenticated one record against a traveler’s known Manchester Airport purchase history. Samples included booking and purchase references, products purchased, prices, parking dates and times, IP addresses, approximate locations, device information and historical spending. The publication said it saw no payment-card or bank-account information.
FulcrumSec also supplied roughly 21.5 GB Manchester customer export containing consolidated customer profiles, booking histories and marketing classifications. The group claims the overall theft amounted to 86 GB and included nearly 200,000 records concerning travel scheduled during the remainder of 2026. BleepingComputer said it could not independently establish the total amount stolen or verify the claim about upcoming-travel records.
The group says exposed API credentials provided its route into the data. FulcrumSec told BleepingComputer that it used airport-specific credentials for Iterable, a customer-engagement platform, that were exposed in client-side JavaScript. MAG has not confirmed that account of the intrusion. Asked about the 86 GB figure, exposed credentials and future-travel records, the company declined to address those claims specifically.
MAG has said about 8.7 million customers were affected, with only email addresses exposed for the “vast majority.” The company says it has contacted affected customers, including those with upcoming bookings.
The additional booking and travel details could make targeted fraud more convincing. Information tying an individual to a particular airport, vehicle, parking period or purchased service could be incorporated into phishing emails, text messages or calls. MAG has advised customers to be alert to suspicious communications and says it will not unexpectedly request payment-card details, banking information or passwords.
Sponsored byCSC
Sponsored byRadix
Sponsored byVerisign
Sponsored byIPv4.Global
Sponsored byWhoisXML API
Sponsored byDNIB.com
Sponsored byVerisign