FulcrumSec Hackers Claim Manchester Airports Group Data Breach

FulcrumSec Hackers Claim Manchester Airports Group Data Breach

Listen to this article

0:00

Press play to start listening

The financially motivated extortion group FulcrumSec has claimed responsibility for the Manchester Airports Group (MAG) breach, saying it stole approximately 86GB of customer, booking and travel data.

Hackread.com reported on August 27 that the incident affected around 8.7 million customers of Manchester, London Stansted and East Midlands airports. MAG initially disclosed that email addresses, phone numbers, postcodes and vehicle registration numbers had been obtained.

FulcrumSec has now supplied data samples that appear to contain considerably more information than those four categories.

Samples Include Detailed Booking Records

According to a report, FulcrumSec provided samples of the information it claims to have stolen. One record was validated by comparing it with a traveller’s known Manchester Airport purchase history.

That record correctly listed previous Fast Track purchases, booking and scheduled arrival times, terminals, amounts paid, purchase references, total spending and the apparent purposes of previous journeys.

The material also included what appeared to be a 21.5GB Manchester customer export containing consolidated profiles. These combined customer identifiers with historical booking activity and marketing classifications.

Other sampled records reportedly contained airport and product selections, prices, discounts, booking statuses, parking dates and times, IP addresses, approximate locations, device information and customer engagement data. The report said no payment-card or bank-account information was found in the samples examined.

Validating one record provides evidence that FulcrumSec possesses authentic MAG customer information. It does not independently establish that the group stole the claimed 86GB or confirm the full extent of its access.

Group Claims Access Through Iterable Credentials

FulcrumSec alleges that it accessed the information using airport-specific Iterable API credentials found in client-side JavaScript. Iterable is a customer engagement platform used to manage customer profiles, communications, and marketing activity.

Iterable’s security documentation states that client-side keys have restricted permissions and should use JWT authentication. It also warns that server-side API keys must never be embedded in browser-delivered code because they can provide access to project data.

Neither MAG nor Iterable has confirmed what type of credentials were involved, what permissions they carried, or whether the alleged access method is accurate.

FulcrumSec also claims the stolen material contains nearly 200,000 records concerning travel planned during the remainder of 2026. According to the group, these records include dates, times, and booking information connected with personally identifiable information.

The group said it intends to publish the stolen data and a technical explanation of the intrusion. However, it is reportedly considering withholding or redacting future-travel records because their publication could cause physical harm or assist criminals.

FulcrumSec Hackers Claim Manchester Airports Group Data Breach
Screenshot of FulcrumSec’s dark web onion site showing its “Wall of Shame” and alleged victims. Manchester Airports Group was not listed at the time of writing. (Image credit: Hackread.com)

MAG Does Not Confirm FulcrumSec Attribution

When asked about FulcrumSec’s attribution claim, the alleged 86GB dataset, the Iterable credentials and the future-travel records, MAG declined to address the claims directly.

The airport operator said it had contacted everyone affected, including customers with upcoming bookings, and provided those travellers with additional support. That response does not confirm FulcrumSec’s identity or its account of the attack.

MAG’s public incident notice continues to list email addresses, phone numbers, vehicle registrations and postcodes as the affected data. It states that bank and payment information was not held in the compromised system.

Airport operations, passenger safety and aviation security were not affected.

Extortion Instead of File Encryption

FulcrumSec has operated since 2025 as a data-extortion group. Its method centres on stealing corporate information and threatening publication rather than encrypting systems and disrupting operations.

The group has previously claimed attacks against LexisNexis, Novo Nordisk, Global Schools Group and Avnet. FulcrumSec reportedly said MAG appeared unwilling to meet its demands, but no ransom amount was disclosed.

For affected customers, the greatest immediate risk remains targeted fraud. Access to real booking references, parking dates, terminals, vehicles and travel plans would allow criminals to create convincing messages about cancelled bookings, payment problems, parking changes or Fast Track services.

Customers should verify communications directly through official airport websites and avoid using telephone numbers or links supplied in unexpected messages. FulcrumSec’s attribution, alleged entry method, 86GB theft claim and figure of nearly 200,000 upcoming travel records remain unconfirmed by MAG.

I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism.

Image by JESHOOTS-com from Pixabay

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts