A criminal hacking group has published personal data belonging to nearly 8.7 million customers of Manchester, London Stansted and East Midlands airports after breaching Manchester Airports Group's systems. The attackers had demanded a ransom, which MAG did not pay, and have now released roughly half a terabyte of stolen information—including contact details, vehicle registrations and postcodes—free of charge to other criminals via their own website.
bbc.co.uk
· 2026-09-02
Extortion group FulcrumSec has claimed responsibility for a breach at Manchester Airports Group, saying it stole roughly 86GB of customer data across Manchester, London Stansted and East Midlands airports. BleepingComputer verified sample records against a real traveler's purchase history, finding detailed booking, payment and travel information beyond what MAG initially disclosed. The hackers allege they used exposed Iterable API credentials found in client-side JavaScript to access the data, including nearly 200,000 records tied to travel scheduled through 2026.
bleepingcomputer.com
· 2026-08-30
Manchester Airports Group revealed that attackers infiltrated its systems and extracted customer information tied to Wi-Fi registrations, car park bookings, lounge access and Fast Track services at Manchester, Stansted and East Midlands airports. Stolen data reportedly includes email addresses, phone numbers, vehicle registration numbers and postcodes, though no payment card details were taken. The company has paused its online booking management tool and shifted customers to phone support while it investigates with outside cybersecurity help and law enforcement.
bleepingcomputer.com
· 2026-08-27