Press play to start listening
FulcrumSec, a data-extortion group, has posted download links for files it claims contain customer and booking information stolen from Manchester Airports Group (MAG), following its earlier threat to release the material.
Hackread.com reviewed the group’s onion-site post and accompanying screenshot on September 1. We did not download the archives or test the links, and we will not reproduce any names, contact details, number plates, booking references or travel dates displayed by the group.
MAG disclosed the breach on August 27 and notified about 8.7 million customers of Manchester, London Stansted and East Midlands airports. FulcrumSec claimed responsibility several days later, initially putting the stolen material at about 86 GB.
FulcrumSec Posts Links to Four Data Archives
The new post lists four archives associated with Manchester, Stansted, East Midlands and a customer database. The compressed sizes shown beside the links add up to roughly 74.5 GB. FulcrumSec labels the release as about 549 GB and says the files occupy roughly 550 GB after extraction. Those figures do not reconcile with its earlier 86 GB claim.
According to the descriptions published with the links, the archives contain 8,672,291 customer profiles and more than 1.16 billion customer engagement events. In this context, “events” refers to activities such as message deliveries, opens and clicks, not separate people or cyber incidents.
Other figures in the post include about 2.48 million purchase records, 461,433 rendered text messages and 108,077 unique vehicle registration numbers. FulcrumSec says the purchase records concern airport parking, lounges and Fast Track services.
In addition to the information MAG disclosed, the post lists names, mobile numbers, hometowns, postal regions, residential IP addresses and booking histories. FulcrumSec also alleges that some records use email domains associated with government, courts, police, fire services, the armed forces, healthcare and media. None of those new claims has been independently verified.
New Claims Go Further Than MAG’s Disclosure
MAG’s public incident notice lists email addresses, telephone numbers, vehicle registration numbers and postcodes among the accessed information. MAG previously said email addresses accounted for most of the affected information, meaning not every customer had every listed field exposed.
The company says neither MAG nor the accessed system held customers’ bank or payment details. Airport operations, flights and parking services continued normally, while passenger safety and aviation security were unaffected. MAG’s notice had not been updated to address FulcrumSec’s publication at the time of writing.
FulcrumSec again claims it gained access to the Iterable customer engagement platform via administrative keys embedded in website code delivered to visitors’ browsers. Neither MAG nor Iterable has confirmed the account of how the breach occurred.
FulcrumSec also claims MAG declined to pay its extortion demand. MAG has not confirmed receiving such a demand or disclosed whether it communicated with the group.
Future Booking Records Present Added Risks
FulcrumSec says it removed details of upcoming travel for about 200,000 passengers from the leak before publication. Later, in the same post, the group says its purchase ledger contained 190,849 bookings dated September 1 or later, including 142,755 records pairing a purchaser’s email address with a vehicle registration.
Because Hackread.com did not download the files, we cannot verify whether those future-booking records were removed, partly redacted or left intact in the published archives.
The post further complicates the withholding claim by stating that the schedule is “now public” and displaying a table of 20 partly redacted profiles. Surnames and sections of email addresses were concealed, but the table displayed first names, full vehicle registration plates, airports, journey directions and future travel dates. Hackread.com is not republishing those details.
If authentic, future booking information could reveal when a customer expects to be away and could help criminals create convincing messages about parking, lounges or flight-related services. Correct details about an airport, booking or vehicle do not prove that a message is genuine.
Customers should verify unexpected communications through the official airport websites or their existing booking accounts. They should not follow links or provide payment information solely because a sender knows a real postcode, telephone number, number plate or booking detail.




