What Happened
- On 25 August 2026, Manchester Airports Group (MAG), the operator of Manchester Airport, London Stansted Airport, and East Midlands Airport, reported they recently suffered data breach.
- Personal information belonging to approximately 8.7 million customers was reportedly accessed. The majority of affected records involve email addresses collected via in-airport Wi-Fi sign ups, alongside customer data from car parking, airport lounge, and Fast Track security bookings.
- According to BBC reports, the cybercriminals behind the attack issued a ransom demand to MAG. MAG said it had to temporarily suspended access to its online "Manage My Booking" service but importantly said that passenger safety, aviation security, and flight operations remained uncompromised and operated normally.
- On 30 August, the MAG breach was then claimed by an known data extortion group called FulcrumSec, which told BleepingComputer that it stole approximately 86 GB of data.
- The FulcrumSec group claims it obtained access using airport-specific Iterable API credentials exposed in client-side JavaScript and that the stolen material includes nearly 200,000 records related to upcoming travel during the remainder of 2026.
Analyst Comment
This breach highlights a common cyber risk pattern around secondary customer services (Wi-Fi portals, parking systems, lounge bookings) often present softer targets than core operational networks. While MAG’s air traffic control and aviation security systems remained segregated and secure, external customer-facing web applications harboured large volumes of Personally Identifiable Information (PII). Although the no payment card details were stolen, the exfiltrated dataset (email, phone, home postcode, vehicle registration) is ideal for tailored targeted phishing and smishing (SMS scams) campaigns, as well as identity theft fraud.
The ransom demand cited by the BBC and claims by FulcrumSec reflects the modern trend of cybercriminals increasingly focus on exfiltrating sensitive PII for extortion, monetising stolen data foregoing the need to encrypt internal infrastructure and cause operational downtime.
The reason MAG’s system was exploited was allegedly due to exposed API credentials in client-side JavaScript. Notably, this is a well-known TTP of FulcrumSec who has stated they leveraged the same issue to target Arup.
While many cybercriminals utilise stolen PII for financial fraud and phishing, state-sponsored advanced persistent threat (APT) groups are likely to also look to exploit this specific combination of datasets as a goldmine for espionage, counter-intelligence, surveillance, and strategic targeting.
Defensive Takeaways
- Hunt for Credential Exposure: FulcrumSec has had success multiple times identifying exposed credentials in web app code. Arup Group was also victimised this way. This highlights the importance of thorough and continuous testing during active development and changes pushed to production environments. A basic procedural review of the application’s security could have caught and mitigated this issue.
- Review Your Security Architecture: This breach highlighted the importance of segregated ancillary web platforms (such as guest Wi-Fi and parking reservation tools) from core networks. Due to segregation, MAG was able to suspend certain portals while keeping core business operations running without significant disruption.
- Proactive Public Communication: MAG did well to proactively issue clear public guidance advising customers on what was and was not taken, helping mitigate downstream fraud risk before attackers exploit the data and before the threat actors publicly claimed the breach.
Relevant Sources
- https://www.bbc.co.uk/news/articles/c7v4353rry7o
- https://www.manchesterairport.co.uk/help/data-security-incident/
- https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/
- https://ico.org.uk/media/action-weve-taken/mpns/2618421/ba-penalty-20201016.pdf
- https://scotthelme.co.uk/no-hacking-required-manchester-airports-group-data-breach/
Relevant CTI Sources
Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.
Enroll Now and Save 10%: Coupon Code MWNEWS10
Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.
Article Link: UK Cybercrime Journal: Manchester Airport Group Breached by FulcrumSec
