Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Breaking News: Manchester Airports Group Suffers Catastrophic Data Breach at the Hands of Extortion Group FulcrumSec


Manchester Airports Group has suffered a catastrophic data breach, with Extortion Group FulcrumSec claiming to have stolen 86GB of sensitive customer data. The breach, which affected 8.7 million customers, has raised concerns about the potential for attackers to use the stolen data for malicious purposes.

  • The Manchester Airports Group (MAG) suffered a devastating data breach, with approximately 86GB of sensitive customer data stolen.
  • The breach affected 8.7 million customers across three airports: Manchester, London Stansted, and East Midlands.
  • Data exposed includes email addresses, phone numbers, vehicle registrations, and postcodes.
  • Extortion Group FulcrumSec claims to have stolen significantly more detailed data, including personal identifiers, historical booking details, and marketing information.
  • Attackers can use stolen data to craft convincing phishing messages targeting people with upcoming trips.
  • Security researchers flag a supply-chain angle, highlighting the risk of third-party platform vulnerabilities.



  • The Manchester Airports Group (MAG) has recently suffered a devastating data breach, in which Extortion Group FulcrumSec has stolen approximately 86GB of sensitive customer data. The breach, which occurred on August 27, affected 8.7 million customers across three airports: Manchester, London Stansted, and East Midlands.

    According to the group's own statement, the data breach primarily exposed email addresses, phone numbers, vehicle registrations, and postcodes. However, in stark contrast, Extortion Group FulcrumSec claims that they stole significantly more detailed data, including personal identifiers, historical booking details, and marketing information.

    The group alleges that they obtained access to the system using airport-specific Iterable API credentials that were exposed in client-side JavaScript. This code is executed in users' browsers, making it easily accessible to anyone with developer tools. The stolen material, according to FulcrumSec, includes nearly 200,000 records related to upcoming travel during the remainder of 2026, complete with dates, times, and booking details linked to identifiable individuals.

    The most concerning aspect of this breach is the potential for attackers to use the stolen data to craft convincing phishing messages targeting people with upcoming trips. UK postcodes can identify very small groups of addresses, combined with vehicle registrations, parking dates, and specific booking references, making this exposure sharper than the equivalent breach might be in the US.

    Security researchers have also flagged a supply-chain angle worth watching. Airport operations increasingly run through third-party platforms for booking, parking, and loyalty services, and Iterable, the marketing platform whose API credentials FulcrumSec claims to have abused, is exactly that kind of outsourced dependency.

    The incident has prompted travelers who recently booked parking, lounge access, or Fast Track services to assume more travel data may be exposed and to treat messages citing real booking details with caution.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Breaking-News-Manchester-Airports-Group-Suffers-Catastrophic-Data-Breach-at-the-Hands-of-Extortion-Group-FulcrumSec-ehn.shtml

  • https://securityaffairs.com/198143/cyber-crime/extortion-group-fulcrumsec-claims-86gb-manchester-airports-group-data-theft.html


  • Published: Sun Aug 30 13:52:44 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us