476/69 Tuesday, September 1, 2026

Manchester Airports Group (MAG), the operator of Manchester, London Stansted, and East Midlands airports, disclosed a data breach on August 27, 2026, stating that the incident affected approximately 8.7 million customers, most of whom had only their email addresses exposed. The affected data was related to bookings for parking, lounges, Fast Track services, and Airport WiFi registrations, and may include email addresses, phone numbers, vehicle registration numbers, and postcodes. An extortion group named FulcrumSec later claimed responsibility for the incident, stating that it had stolen approximately 86 GB of data from MAG, allegedly containing more details than the company initially disclosed.
FulcrumSec claimed that it gained access through airport-specific Iterable API credentials exposed in client-side JavaScript, which is code that runs in users’ browsers. This means that anyone inspecting the website through Developer Tools may have been able to view the credentials. If this claim is accurate, the attackers would not have needed sophisticated techniques and could have used credentials exposed in the website code to access data. A data sample provided by the group to BleepingComputer for verification reportedly included a 21.5 GB export of Manchester customer data containing personally identifiable information, booking history, and marketing data. One sample record was checked and found to match a traveler’s real purchase history, including a Fast Track booking, arrival time, terminal information, and the amount paid.
FulcrumSec also claimed that the stolen data included nearly 200,000 records related to upcoming travel during the remainder of 2026, potentially including dates, times, and booking details linked to personal information. However, this figure and the full scope of the stolen data have not been independently verified. MAG did not directly respond to the claims regarding the 86 GB of data or exposed API credentials, but stated that it had contacted affected individuals with future bookings and confirmed that no payment card or bank account information was exposed. Users who have booked parking, lounge, or Fast Track services with MAG airports should remain cautious of emails or messages that reference real booking details, as information such as UK postcodes, vehicle registration numbers, parking dates, and booking information could be used to create highly convincing phishing attacks.
