Manchester Airports Group Hit by Massive Data Breach, Exposing Sensitive Customer Info
A devastating data breach has struck Manchester Airports Group (MAG), compromising sensitive customer information and exposing over 86 gigabytes of data to potential misuse. The attack is claimed by extortion group FulcrumSec, which has a history of targeting organizations with significant financial resources.
According to reports, the hackers exploited airport-specific API credentials left exposed in client-side JavaScript, allowing them to gain unauthorized access to MAG’s systems. This breach appears to be more extensive than initially disclosed, with stolen data including customer identifiers, historical booking activity, marketing classifications, and nearly 200,000 records related to upcoming travel during the remainder of 2026.
FulcrumSec claims to have obtained a massive dataset containing consolidated profiles that combine customer information with booking history. The group has shared samples of the allegedly stolen data with cybersecurity journalist BleepingComputer, which validated one record by comparing it with the traveler’s known Manchester Airport purchase history. The review revealed detailed records containing personal identifiable information (PII), including dates, times, and booking information linked to airport, vehicle, parking, and product selections.
While MAG has acknowledged a breach involving customer data related to car park, lounge, and Fast Track bookings, as well as in-airport Wi-Fi registrations, the company has declined to address FulcrumSec’s specific claims regarding the extent of the dataset and the exposed credentials. In an updated statement, MAG emphasized that affected customers with upcoming bookings had been contacted and offered additional support.
The scope of the breach appears broader than initially suggested, with sampled records containing sensitive information such as vehicle registrations, postcodes, IP addresses, approximate locations, device information, and customer-engagement data. The exposure of UK postcodes is particularly concerning, as these can identify a small group of neighboring properties, allowing attackers to reference a victim’s specific location.
FulcrumSec has stated its intention to publish the stolen data and a technical account of the intrusion, but has expressed concerns about potential “real-world harm” and may withhold or redact sensitive records. The group is known for targeting organizations with significant financial resources and stealing sensitive corporate data rather than encrypting victims’ systems.
The Manchester Airports Group breach serves as a stark reminder of the importance of robust cybersecurity measures in protecting sensitive customer information. Organizations must prioritize secure coding practices, regularly update credentials, and monitor systems for potential vulnerabilities to prevent similar attacks in the future.
For individuals affected by this breach, it’s essential to remain vigilant and monitor their accounts closely for suspicious activity. If you’re a Manchester Airports Group customer with upcoming bookings, be sure to review any additional support offered by MAG carefully and take steps to protect your sensitive information.
Source: Bleeping Computer — 2026-08-30