The Manchester Airports Group (MAG), operator of Manchester, London Stansted, and East Midlands airports, recently confirmed a data breach affecting customer information. Extortion group FulcrumSec has claimed responsibility for the attack, asserting that it exfiltrated approximately 86 GB of data.
MAG initially disclosed on August 27 that an unauthorized third party had stolen customer data related to car park, lounge, and Fast Track bookings, as well as in-airport Wi-Fi registrations. FulcrumSec, a financially motivated data-extortion group active since 2025, contacted a cybersecurity news outlet, providing samples of the allegedly stolen data as evidence.
One record from the samples was validated against a traveler's known purchase history, accurately reflecting previous Fast Track purchases, booking and scheduled arrival times, terminal usage, amounts paid, purchase references, total spending, and apparent trip purposes. The material included a 21.5 GB export of Manchester customer data, containing consolidated profiles that combined customer identifiers with historical booking activity and marketing classifications.
FulcrumSec claims to have gained access using airport-specific Iterable API credentials that were exposed in client-side JavaScript. The group further alleges that the stolen material includes nearly 200,000 records pertaining to upcoming travel during the remainder of 2026, which supposedly contain dates, times, booking information, and personally identifiable information. While the samples appeared authentic, the full extent of the attacker's access, the total size of the dataset, and the claim regarding upcoming travel records could not be independently verified.
MAG declined to address FulcrumSec's specific claims regarding the 86 GB dataset, exposed credentials, or future travel data. A spokesperson referred to an updated statement confirming that affected customers with upcoming bookings had been contacted and advised of additional support. MAG is understood to have refused to pay a monetary ransom reportedly demanded by the attackers.
The scope of the breach appears to be broader than initially suggested by MAG's disclosure of email addresses, phone numbers, vehicle registrations, and postcodes. Sampled records contained additional details such as purchase and booking references, airport and product selections, prices, discounts, booking status, parking dates and times, historical spending, IP addresses, approximate locations, device information, and customer engagement data. No payment card or bank account information was observed in the reviewed samples.
The combination of contact, vehicle, and travel information, particularly with precise UK postcodes (which can identify as few as 15 addresses or even a single address), could enable attackers to craft highly convincing phishing emails, text messages, or telephone scams impersonating MAG or booking providers.
MAG has advised affected customers to remain vigilant for suspicious communications, emphasizing that the company would never unexpectedly request payment card details, banking information, or passwords. The incident has not caused operational disruption, and MAG states that passenger safety and aviation security were not compromised.
Previously, MAG indicated that approximately 8.7 million customers were affected, though for the "vast majority," only email addresses were exposed. This incident represents the largest known customer data breach affecting a British airport operator.






