FulcrumSec Claims 86 GB Theft in Manchester Airports Group Breach

The extortion group FulcrumSec claims responsibility for the Manchester Airports Group (MAG) data breach, telling BleepingComputer that it stole approximately 86 GB of data. MAG, the United Kingdom's largest airport operator, disclosed the breach on August 27, saying an unauthorized third party stole customer data tied to Manchester, London Stansted, and East Midlands airports, including car park, lounge, and Fast Track bookings and in-airport Wi-Fi registrations.

FulcrumSec shares samples of the allegedly stolen data with BleepingComputer, which validates one record by comparing it with a traveler's known Manchester Airport purchase history. The material includes a roughly 21.5 GB customer export combining customer identifiers with historical booking activity and marketing classifications. The group says it gained access using airport-specific Iterable API credentials exposed in client-side JavaScript and that the stolen dataset includes nearly 200,000 records related to upcoming travel through the end of 2026.

FulcrumSec says it intends to publish the stolen data and a technical account of the intrusion, though it is considering withholding or redating upcoming-travel records because of potential "real-world harm." While the samples appear authentic, BleepingComputer cannot independently verify the source or extent of the group's access, the total size of the dataset, or the claim about upcoming-travel records. After completing its verification, BleepingComputer securely deletes all supplied material without retaining any of it.

Read More at the original source →