LIVE · cybersecurity feed
Live wire
security

FulcrumSec claims Manchester Airports hack, theft of 86 GB of data

FulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information beyond what MAG initially disclosed. [...]

zeroday.news ·

The Manchester Airports Group (MAG), operator of Manchester, London Stansted, and East Midlands airports, recently confirmed a data breach affecting customer information. Extortion group FulcrumSec has claimed responsibility for the attack, asserting that it exfiltrated approximately 86 GB of data.

MAG initially disclosed on August 27 that an unauthorized third party had stolen customer data related to car park, lounge, and Fast Track bookings, as well as in-airport Wi-Fi registrations. FulcrumSec, a financially motivated data-extortion group active since 2025, contacted a cybersecurity news outlet, providing samples of the allegedly stolen data as evidence.

One record from the samples was validated against a traveler's known purchase history, accurately reflecting previous Fast Track purchases, booking and scheduled arrival times, terminal usage, amounts paid, purchase references, total spending, and apparent trip purposes. The material included a 21.5 GB export of Manchester customer data, containing consolidated profiles that combined customer identifiers with historical booking activity and marketing classifications.

FulcrumSec claims to have gained access using airport-specific Iterable API credentials that were exposed in client-side JavaScript. The group further alleges that the stolen material includes nearly 200,000 records pertaining to upcoming travel during the remainder of 2026, which supposedly contain dates, times, booking information, and personally identifiable information. While the samples appeared authentic, the full extent of the attacker's access, the total size of the dataset, and the claim regarding upcoming travel records could not be independently verified.

MAG declined to address FulcrumSec's specific claims regarding the 86 GB dataset, exposed credentials, or future travel data. A spokesperson referred to an updated statement confirming that affected customers with upcoming bookings had been contacted and advised of additional support. MAG is understood to have refused to pay a monetary ransom reportedly demanded by the attackers.

The scope of the breach appears to be broader than initially suggested by MAG's disclosure of email addresses, phone numbers, vehicle registrations, and postcodes. Sampled records contained additional details such as purchase and booking references, airport and product selections, prices, discounts, booking status, parking dates and times, historical spending, IP addresses, approximate locations, device information, and customer engagement data. No payment card or bank account information was observed in the reviewed samples.

The combination of contact, vehicle, and travel information, particularly with precise UK postcodes (which can identify as few as 15 addresses or even a single address), could enable attackers to craft highly convincing phishing emails, text messages, or telephone scams impersonating MAG or booking providers.

MAG has advised affected customers to remain vigilant for suspicious communications, emphasizing that the company would never unexpectedly request payment card details, banking information, or passwords. The incident has not caused operational disruption, and MAG states that passenger safety and aviation security were not compromised.

Previously, MAG indicated that approximately 8.7 million customers were affected, though for the "vast majority," only email addresses were exposed. This incident represents the largest known customer data breach affecting a British airport operator.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

malware

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. [...]

malware

Chrome Web Store extensions caught stealing crypto, browser data

Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, as well as inject ClickFix lures. [...]

malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 112

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor FTP Banners: The New Dead Drop Resolver Delivering Novel RATs The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic […]

vulnerabilityhigh

Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch

PaperCut servers are under active attack, while 47% of tracked installations still run unpatched versions vulnerable to remote code execution. PaperCut, the print management software running in schools, hospitals, and offices worldwide, confirmed on August 27 that a pre-authentication remote code execution flaw is being actively exploited against real customers. Researchers at Huntress found evide