"MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support," a Manchester Airports Group spokesperson told BleepingComputer.
FulcrumSec claims responsibility and an 86 GB haul
FulcrumSec, a financially motivated data-extortion group active since 2025, told BleepingComputer it is responsible for the Manchester Airports Group (MAG) intrusion and that it stole approximately 86 GB of data. The group supplied samples to BleepingComputer and said it intends to publish the stolen material and a technical account of the intrusion, though it told the publication it may withhold or redact records because of potential "real-world harm."
Alleged method: exposed Iterable API credentials in client-side JavaScript
FulcrumSec claimed the group obtained access using airport-specific Iterable API credentials exposed in client-side JavaScript. The samples provided included a roughly 21.5 GB Manchester customer export containing consolidated profiles that combined customer identifiers with historical booking activity and marketing classifications.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWhat BleepingComputer reviewed and verified
BleepingComputer examined the samples FulcrumSec supplied. The publication validated one record by comparing it with a traveller's known Manchester Airport purchase history; that record accurately listed previous Fast Track purchases, booking and scheduled-arrival times, the terminal used, amounts paid, purchase references, total spending and the apparent purpose of the trips. In the sampled material BleepingComputer observed data beyond MAG's initial disclosure, including purchase and booking references, airport and product selections, prices, discounts, booking status, parking dates and times, historical spending, IP addresses, approximate locations, device information and customer-engagement data.
BleepingComputer did not observe payment-card or bank-account information in the reviewed samples. After completing its verification, BleepingComputer securely deleted all supplied material without retaining copies and will not publish or share any part of it. The publication also noted it could not independently verify the alleged source or extent of the threat actor's access, the overall size of the stolen dataset, or the claim concerning nearly 200,000 upcoming-travel records.
MAG's disclosure, customer contact, and operational impact
MAG disclosed on August 27 that an unauthorized third party had stolen customer data related to Manchester, London Stansted, and East Midlands airports. The company said affected information came from car park, lounge and Fast Track bookings and in-airport Wi‑Fi registrations. A MAG spokesperson declined to address FulcrumSec's specific claims to BleepingComputer, instead referring to the updated statement about contacting affected customers. MAG said it had reached out to all those with upcoming bookings to offer additional support, and stressed it would never contact customers unexpectedly to request payment-card details, banking information, or passwords.
The incident has not caused operational disruption, and MAG said passenger safety and aviation security were not compromised. A MAG spokesperson previously told the Manchester Evening News that around 8.7 million customers were affected, although only email addresses were exposed for the "vast majority." That figure makes this the largest known customer data breach affecting a British airport operator, based on MAG's earlier statement.
Data specifics, UK postcodes, and phishing risk
Beyond email addresses, phone numbers, vehicle registrations and postcodes named in MAG's disclosure, the sampled records contained granular details that could enable targeted social‑engineering: booking dates and times, vehicle and parking details, purchase references, booking status and historical spending, alongside IP addresses and device information. The reporting underscored that a full UK postcode can identify a small group of neighboring properties — the UK Office for National Statistics notes a typical small‑user postcode covers approximately 15 addresses, and some postcodes are assigned to a single address. Combined with contact, vehicle and travel information, those details could be used to craft convincing phishing emails, text messages or telephone scams impersonating MAG or a booking provider.
What this means for technologists, affected customers, and booking providers
- Technologists and security teams: will want to review how API credentials are exposed in client-side code, since FulcrumSec attributes access to Iterable API credentials exposed in JavaScript.
- Affected customers: MAG says it has contacted those with upcoming bookings and advised vigilance for suspicious emails, texts and telephone calls; MAG reiterated it would not request payment details, banking information or passwords unexpectedly.
- Booking providers and airport services: may face elevated fraud risk if the alleged consolidated profiles and booking metadata are published or circulated, because those records include purchase references, product selections and booking status that could be replayed in scams.
FulcrumSec's claim — the 86 GB figure, the 21.5 GB Manchester export, and the assertion of nearly 200,000 upcoming-travel records — stands in tension with MAG's refusal to address the specific allegations and BleepingComputer's inability to independently verify the full scope. MAG has told affected customers it has taken measures and contacted those with upcoming bookings; whether FulcrumSec follows through with publication or redaction will determine how widely the additional details circulate.




