Back to feed

Hackers publish 8.7 million records stolen from Manchester Airports Group

2 min
Hackers publish 8.7 million records stolen from Manchester Airports Group

This digest was compiled by AI from multiple sources — links to the originals are below.

Hackers have published all 8.7 million records stolen from Manchester Airports Group, affecting customers of Manchester, London Stansted, and East Midlands airports. The data includes email addresses, phone numbers, vehicle registrations, and postcodes, but no bank or payment details. The group FulcrumSec claimed responsibility after MAG refused to pay a ransom.

Key Facts

  • The published dataset includes 8,672,291 customer profiles, 1.169 billion marketing events, 2,482,763 purchases, 461,433 SMS messages, and 108,077 vehicle registrations.
  • MAG disclosed the cyberattack on August 27th, stating that data from approximately 8.7 million customers was accessed through WiFi registrations and car park, lounge, and Fast Track bookings.
  • FulcrumSec claimed that visible website keys on the root domain made the breach easy, and MAG refused to pay the ransom demanded for the data's return.
  • MAG stated that the affected systems did not hold bank or payment details, and that passenger safety and airport operations were not compromised.

Data Publication and Contents

On Wednesday, criminals published all the data they stole from Manchester Airports Group, according to a BBC report. The dark web post by FulcrumSec listed 8,672,291 customer profiles, 1.169 billion marketing events, 2,482,763 purchases, 461,433 SMS messages, and 108,077 vehicle registrations. The stolen data also includes email addresses, phone numbers, postcodes, vehicle registrations, and future booking information. MAG stated that the vast majority of affected customers had only their email addresses exposed.

Attack and Extortion Attempt

FulcrumSec claimed responsibility for the attack and said that visible website keys on the root domain made the breach easy. The group stated that the keys were not on an obscure subdomain but visible to any visitor using the browser's inspect tool. MAG refused to pay the ransom demanded by the hackers, in line with advice from governments and cybersecurity agencies. The hackers warned that some records belong to public figures, politicians, and military personnel, potentially exposing victims to physical threats.

Company Response

MAG stated that neither the company nor the accessed system held customers' bank or payment details. The company said it has contacted all those affected, including reaching out to customers with upcoming bookings to offer additional support. MAG expressed confidence that effective measures have been taken to protect customers.

2 sources

Time · lag behind first