mimile
Back to feed

FulcrumSec claims Manchester Airports Group hack, theft of 86 GB of data

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

FulcrumSec claims Manchester Airports Group hack, theft of 86 GB of data

Extortion group FulcrumSec claims responsibility for the Manchester Airports Group data breach, saying it stole approximately 86 GB of data. Samples reviewed by BleepingComputer contained information consistent with MAG's disclosure while indicating the breach exposed more detailed customer, booking, and travel information than initially revealed. MAG has not addressed the hackers' claims.

Key Facts

  • Manchester Airports Group disclosed on August 27 that an unauthorized third party stole customer data related to Manchester, London Stansted, and East Midlands airports.
  • FulcrumSec claims it stole approximately 86 GB of data, including a 21.5 GB Manchester customer export with consolidated profiles and historical booking activity.
  • The group says it obtained access using airport-specific Iterable API credentials exposed in client-side JavaScript.
  • FulcrumSec claims the stolen material includes nearly 200,000 records related to upcoming travel during the remainder of 2026.
  • BleepingComputer could not independently verify the alleged source, extent of access, overall dataset size, or the claim concerning nearly 200,000 upcoming-travel records.

Breach Disclosure

Manchester Airports Group, the United Kingdom's largest airport operator, disclosed on August 27 that an unauthorized third party had stolen customer data related to Manchester, London Stansted, and East Midlands airports. The company said the affected information came from car park, lounge, and Fast Track bookings and in-airport Wi-Fi registrations. FulcrumSec told BleepingComputer that it stole approximately 86 GB of data, a figure MAG has not confirmed.

Hacker Claims and Evidence

In emails to BleepingComputer, FulcrumSec claimed responsibility for the attack and shared samples of the allegedly stolen data as evidence. BleepingComputer validated one record by comparing it with the traveller's known Manchester Airport purchase history; the record accurately listed previous Fast Track purchases, booking and scheduled-arrival times, the terminal used, amounts paid, purchase references, total spending and the apparent purpose of the trips. The material included a roughly 21.5 GB Manchester customer export containing consolidated profiles that combined customer identifiers with historical booking activity and marketing classifications. FulcrumSec claims it obtained access using airport-specific Iterable API credentials exposed in client-side JavaScript. The group says the stolen material includes nearly 200,000 records related to upcoming travel during the remainder of 2026, allegedly containing dates, times and booking information linked to personally identifiable information.

Verification and Response

While the samples appeared authentic, BleepingComputer could not independently verify the alleged source or extent of the threat actor's access, the overall size of the stolen dataset, or the claim concerning nearly 200,000 upcoming-travel records. After completing its verification, BleepingComputer securely deleted all supplied material without retaining copies and will not publish or share any part of it. FulcrumSec is a financially motivated data-extortion group active since 2025 that focuses on stealing sensitive corporate data and threatening to publish it rather than encrypting victims' systems. The group has previously claimed attacks on organizations including LexisNexis, Novo Nordisk, Global Schools Group, and Avnet. BleepingComputer contacted MAG again before publication and asked the company to address FulcrumSec's claims concerning the 86 GB dataset, exposed credentials and future-travel data; MAG has not responded.

1 source

FulcrumSec claims Manchester Airports Group hack, theft of 86 GB of data