Skip to content
Tech News
← Back to articles

FulcrumSec claims Manchester Airports hack, theft of 86 GB of data

read original more articles
Why This Matters

The Manchester Airports Group data breach, claimed by FulcrumSec, exposes sensitive customer and travel data, highlighting vulnerabilities in airport cybersecurity. This incident underscores the increasing sophistication of cyber threats targeting critical infrastructure and the importance of robust data protection measures for both industry operators and consumers. The breach's potential impact on traveler privacy and operational security emphasizes the urgent need for enhanced cybersecurity protocols in the aviation sector.

Key Takeaways

The Manchester Airports Group data breach has been claimed by extortion group FulcrumSec, which told BleepingComputer that it stole approximately 86 GB of data.

Samples reviewed by BleepingComputer contained information consistent with MAG's disclosure while indicating that the breach exposed considerably more detailed customer, booking, and travel information than initially revealed.

Hackers claim theft of 86 GB of data

Manchester Airports Group (MAG), the United Kingdom's largest airport operator, disclosed on August 27 that an unauthorized third party had stolen customer data related to Manchester, London Stansted, and East Midlands airports.

The company said the affected information came from car park, lounge, and Fast Track bookings and in-airport Wi-Fi registrations.

In emails to BleepingComputer, FulcrumSec claimed responsibility for the attack and shared samples of the allegedly stolen data as evidence.

BleepingComputer validated one record by comparing it with the traveller's known Manchester Airport purchase history.

The record accurately listed previous Fast Track purchases, booking and scheduled-arrival times, the terminal used, amounts paid, purchase references, total spending and the apparent purpose of the trips.

The material included a roughly 21.5 GB Manchester customer export containing consolidated profiles that combined customer identifiers with historical booking activity and marketing classifications.

The group claims it obtained access using airport-specific Iterable API credentials exposed in client-side JavaScript and that the stolen material includes nearly 200,000 records related to upcoming travel during the remainder of 2026.

... continue reading