Skip to main content
Emerging ThreatsData Breaches

FulcrumSec Leaks 550GB of Manchester Airport Group Customer Data

Airport scene with luggage cart, scattered bags, and blurred laptop screen.

"pure PII," FulcrumSec wrote as it posted what it said was almost all of the 550GB of data it stole from the Manchester Airport Group for download on its leak site.

FulcrumSec's claim and the scale of the publication

FulcrumSec posted what it said was roughly 549GB of uncompressed data taken from Manchester Airport Group (MAG) systems. The group claimed the cache includes nearly 8.7 million customer profiles and a range of other records it characterised as “pure PII.” The post describes a much broader sweep of customer information than had been publicly disclosed by MAG prior to the leak.

Specific data types FulcrumSec says it exfiltrated

According to the group’s post, the dataset includes:

  • Nearly 8.7 million customer profiles containing email, name, mobile number, home town, postcode and residential IP address;
  • Nearly 1.2 billion marketing events, including sends, opens and clicks;
  • Nearly 2.5 million purchases — recorded as “every booking that customers of parking, Fast Track and lounges have ever made”;
  • Over 461,000 SMS messages holding passenger booking dates, car park and vehicle registration in plain text;
  • 108,000 unique vehicle registration plates;
  • Platform configuration data; and
  • Nearly 191,000 future bookings, which the group said include travel schedules, PII and vehicle information.

How FulcrumSec says it gained access: Iterable admin keys in site code

FulcrumSec attributed its initial access to admin keys for the customer engagement platform Iterable. The group said it discovered those keys embedded in the frontend JavaScript on the root domain of each of MAG’s three airport websites — Manchester Airport, Stansted Airport and East Midlands Airport.

In its note the group contrasted this with prior intrusions, writing: “These keys were not found on some obscure subdomain, as was the case with the credentials that led to our breaches of Arup Group and Novo Nordisk. All three of these were on the sites’ root domain.” It added: “No subdomain enumeration or URL crawling necessary; any of the millions of visitors to the site could have right-clicked ‘inspect’ and seen the keys just sitting there, plain as day. On all three websites.”

Potential harms the group highlights

FulcrumSec warned that the combination of data it says it has taken could enable follow-on fraud and physical targeting. The group pointed specifically to the nearly 191,000 future bookings it claims to hold, saying those records include travel schedules and vehicle information that could be used “by criminals to physically target holidaymakers’ homes.”

The post also asserts that some of the booked individuals are likely public figures, politicians and military staff, deduced from associated email addresses. The group said that, prior to publication, it “removed the most sensitive parts … from the leak” because, it claimed, “MAG declined to pay the necessary fee to protect their passengers’ data.”

Where MAG stands

The Manchester Airport Group has provided limited public detail. The source material notes that MAG “has not provided any update since its original post on August 27.” The claims published by FulcrumSec have not been independently verified in the material released with the group’s announcement; the group framed the figures and contents as its own assertions.

What this means for technologists, passengers, and MAG leadership

  • Technologists and security teams: The disclosure highlights a claimed vector — admin keys placed in frontend JavaScript tied to a customer engagement platform — that the group says made access straightforward. Teams responsible for third‑party integrations and frontend code will be watching for exposed credentials and platform configuration leaks of the sort FulcrumSec described.
  • Passengers and booking customers: If the group’s figures are correct, millions of profiles, hundreds of thousands of SMS messages and nearly 191,000 future bookings could contain information usable for phishing, impersonation and, as the group warned, physical targeting tied to travel schedules and vehicle details.
  • MAG leadership and procurement: The group’s post raises questions about how platform credentials and configuration data were managed across MAG’s three airport web presences. MAG’s lack of a public update after its August 27 post, as noted in the published material, increases urgency for clear communication with affected customers and for verification of the claims FulcrumSec has made.

The record released by FulcrumSec, if accurate, represents a large and varied trove of customer data tied to three major airport properties. The group’s account links the breach to exposed Iterable admin keys in site code and outlines both immediate — phishing and fraud — and physical safety risks tied to future bookings. The claims remain those of the group and, according to the available material, MAG has not offered a subsequent public update since August 27.

Original reporting: Infosecurity Magazine