FulcrumSec claims Manchester Airports hacked, 86GB of data stolen

airport

The Manchester Airports Group data breach was reported by extortion group FulcrumSec, which told BleepingComputer it stole approximately 86GB of data.

Samples reviewed by BleepingComputer contained information consistent with MAG’s disclosures, while also showing that the breach exposed significantly more detailed information about customers, bookings and trips than was initially disclosed.

Hackers claim to have stolen 86 GB of data

Manchester Airports Group (MAG), the UK’s largest airport operator, disclosed on August 27 that an unauthorized third party had stolen customer data relating to Manchester, London Stansted and East Midlands airports.

image

The company said the affected information came from parking, lounge and Fast Track reservations and airport Wi-Fi check-ins.

In emails to BleepingComputer, FulcrumSec claimed responsibility for the attack and shared samples of the allegedly stolen data as evidence.

BleepingComputer confirmed one entry by comparing it to the known purchase history of the Manchester Airport passenger.

The record accurately lists previous Fast Track purchases, reservations and scheduled arrival times, the terminal used, amounts paid, purchase references, total expenses and the apparent purpose of the trips.

The material includes an approximately 21.5 GB customer export from Manchester containing consolidated profiles that combine customer identifiers with past booking activity and marketing classifications.

The group claims it gained access using airport-specific Iterable API credentials exposed in client-side JavaScript, and that the stolen material included nearly 200,000 records related to upcoming travel through the remainder of 2026.

These records are said to contain dates, times and booking information associated with personal information.

FulcrumSec says it intends to publish the stolen data and a technical account of the breach. However, he told BleepingComputer that he was considering withholding or redacting those recordings because of the potential for “real-world harm.”

Although the samples appeared authentic, BleepingComputer could not independently verify the alleged source or extent of access of the threat, the total size of the stolen data set, or the claim of nearly 200,000 records of upcoming trips.

After completing its review, BleepingComputer securely deletes all submitted material without retaining copies and will not publish or share any part of it.

FulcrumSec is a financially motivated data extortion group active since 2025 that focuses on stealing sensitive corporate data and threatening to publish it, rather than encrypting victims’ systems.

The group has previously claimed attacks on organizations including LexisNexis, New Nordisk, Global Schools Groupand Avnet.

MAG refuses to respond to the hackers’ claims

BleepingComputer contacted MAG again ahead of publication and asked the company to respond to FulcrumSec’s claims about the 86GB data set, exposed credentials and future travel data.

A spokesperson declined to respond to the specific claims, instead referring to an updated statement confirming that affected customers with pending bookings had been contacted.

“MAG is confident that we have taken effective measures to protect our customers and have contacted everyone affected, including contacting anyone with pending bookings to advise them of further support,” a MAG spokesperson told BleepingComputer.

The attackers it is reported demanded a ransom, which MAG was understood to have refused to pay.

The range appears to be wider than originally suggested

In addition to the email addresses, phone numbers, vehicle registrations and postal codes revealed by MAG, sample records contained purchase and booking inquiries, airport and product selections, prices, discounts, booking status, parking dates and times, historical costs, IP addresses, approximate locations, device information and customer engagement data.

BleepingComputer does not monitor payment card or bank account information in the samples reviewed.

Unlike US postcodes, which usually cover wider delivery areas, a full UK postcode can identify a small group of contiguous properties. According to The UK Office for National Statistics, the typical postcode for a small user covers approximately 15 addresses, while some postcodes are assigned to a single address.

Combined with contact, vehicle and travel information, these details can allow attackers to reference the victim’s airport, vehicle, parking dates, booking status or purchased services in convincing phishing emails, text messages or phone scams impersonating MAG or a booking provider.

MAG said it had contacted affected customers and advised them to remain vigilant for suspicious emails, texts and phone calls.

The airport operator stressed that it would never contact customers unexpectedly to ask for payment card details, banking information or passwords.

The incident caused no operational disruption and MAG says passenger safety and aviation security were not compromised.

MAG spokesperson earlier said on Manchester Evening News that around 8.7 million customers were affected, although only email addresses were exposed to the “vast majority”.

This makes it the largest known breach of customer data to affect a UK airport operator.

With files from Bill Tulas


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *