Extortion group FulcrumSec has claimed credit for the data breach affecting Manchester Airports Group (MAG), the UK’s largest airport operator, telling BleepingComputer it stole roughly 86 GB of customer and booking data. Samples reviewed by the outlet suggest the exposure is considerably more detailed than MAG originally disclosed.
MAG disclosed on August 27 that an unauthorized third party had stolen customer data tied to Manchester, London Stansted, and East Midlands airports, sourced from car park, lounge, and Fast Track bookings as well as in-airport Wi-Fi registrations.
FulcrumSec provided BleepingComputer with sample records as proof, one of which was validated against a known traveller’s Manchester Airport purchase history. The sample accurately reflected prior Fast Track purchases, booking and arrival times, terminal used, amounts paid, purchase references, and total spending.
Broader exposure than disclosed
The material reviewed included a roughly 21.5 GB Manchester customer export containing consolidated profiles that combined customer identifiers with booking history and marketing classifications. FulcrumSec claims it gained access via airport-specific Iterable API credentials exposed in client-side JavaScript, and alleges the stolen data includes nearly 200,000 records tied to upcoming travel through the rest of 2026, containing dates, times, and PII-linked booking details.
Sampled records reportedly went beyond the email addresses, phone numbers, vehicle registrations, and postcodes MAG initially disclosed, also containing purchase and booking references, product selections, prices, discounts, booking status, parking dates and times, historical spending, IP addresses, approximate locations, device information, and engagement data. No payment-card or bank-account data was observed in the reviewed samples.
BleepingComputer said it could not independently verify the full scope of the claimed intrusion, the total dataset size, or the alleged 200,000 upcoming-travel records, and deleted all supplied material after verification.
MAG response
MAG declined to address FulcrumSec’s specific claims but confirmed it has contacted affected customers, including those with upcoming bookings, and advised vigilance against phishing attempts impersonating the company. The attackers reportedly demanded a ransom, which MAG is understood to have refused to pay.
A MAG spokesperson previously told the Manchester Evening News that approximately 8.7 million customers were affected, though only email addresses were exposed for most of them, making this the largest known customer data breach affecting a British airport operator. FulcrumSec, active since 2025, has previously claimed attacks on LexisNexis, Novo Nordisk, Global Schools Group, and Avnet, and says it plans to publish a technical writeup, though it is weighing redactions to avoid real-world harm.
