Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal

A staggering 8.8 million individuals have had their personal data exposed in a major breach of Manchester Airports Group (MAG) systems. The incident, which occurred after hackers refused to accept a ransom payment, has left thousands of people vulnerable to potential identity theft and other cyber threats.

According to MAG, the attackers breached its systems by exploiting vulnerabilities in the frontend JavaScript code on three airports’ websites: Manchester, London Stansted, and East Midlands. This allowed them to access sensitive information stored in a database hosted by a third-party provider. The stolen data includes email addresses, phone numbers, vehicle registrations, postcodes, and residential IP addresses used to access accounts.

The attackers, who claim responsibility for the breach as part of the FulcrumSec extortion gang, have published approximately 550 gigabytes of uncompressed data online. This dataset contains a wealth of personal information, including names, emails, phone numbers, town and postal region, and residential IP addresses used to access accounts. According to HaveIBeenPwned, which has added the dataset to its database, over 8.8 million email addresses and phone numbers were compromised in the breach.

FulcrumSec claims that the stolen data also includes booking information for parking, lounge, and fast-track products, as well as SMS messages associated with bookings. The attackers have further admitted that they exploited admin keys left in plain sight on the websites to gain access to MAG’s systems. Notably, MAG has confirmed that it refused to pay a ransom demand from the hackers.

The breach raises concerns about the security of sensitive data stored by third-party providers and highlights the importance of robust cybersecurity measures for organizations handling large amounts of personal information. As the number of high-profile breaches continues to grow, it’s essential for individuals and businesses alike to take proactive steps to protect themselves against potential cyber threats.

In practical terms, this breach serves as a reminder that even seemingly secure systems can be vulnerable to exploitation. It’s crucial for organizations to regularly review their security protocols and ensure they are keeping pace with emerging threats. Individuals should also remain vigilant when sharing personal data online and consider taking extra precautions to protect themselves against potential identity theft and other cyber threats.

This incident serves as a stark reminder of the importance of robust cybersecurity measures in today’s digital landscape, where even seemingly secure systems can be vulnerable to exploitation by determined attackers.


Source: SecurityWeek — 2026-09-03