The extortion group FulcrumSec has published the customer dataset it stole from Manchester Airports Group (MAG), operator of Manchester, London Stansted and East Midlands airports, after the company refused to pay its ransom demand. MAG confirmed the intrusion on 27 August 2026 and put the affected population at roughly 8.7 million customers; HaveIBeenPwned, which parsed the dump and ingested it, counts approximately 8.8 million email addresses and phone numbers. The leaked corpus includes names, phone numbers, postcodes, purchase histories, IP addresses and more than 108,000 UK vehicle registration plates. Subsequent analysis of the dump by The Mail on Sunday reports that it contains records tied to a serving circuit judge, parliamentary workers, Home Office and Bank of England staff, Armed Forces members, celebrities and Premier League footballers.
Note on sourcing: no primary-tier document (MAG's own filing, an ICO notice or an NCSC advisory) is in this source set. Every MAG statement quoted below reaches us secondhand through press reporting.
What Happened
MAG disclosed on 27 August 2026 that "an unauthorised third party" had obtained a quantity of customer data relating to car park, lounge and Fast Track bookings and to in-airport WiFi sign-ups across its three airports. The BBC reported that MAG became aware of the compromise on Tuesday 25 August, that the data was taken "at the weekend," and that the company moved quickly to cut off further access. The Mail on Sunday dates the intrusion itself to 22 and 23 August. MAG stated that it contained the risk, engaged specialist advisers, notified the relevant authorities and contacted affected customers, and stressed that "at no point has passenger safety or aviation security been compromised." CTI Pilot notes MAG also suspended its Manage My Booking self-service portal as a precaution.
FulcrumSec claimed the attack over the following weekend. On 30 August it told BleepingComputer it had taken roughly 86 GB of data and supplied samples; BleepingComputer validated one record against a traveller's known Manchester Airport purchase history, confirming Fast Track purchase dates, terminal, amounts paid and booking references. The gang then published the full set on or about 1 to 2 September after extortion attempts were rebuffed. SecurityWeek reports MAG confirmed receiving a ransom demand but declined further detail. Computer Weekly and Security Affairs both describe the release as following MAG's refusal to pay.
What Was Taken
Figures differ depending on who is counting and what is being counted, so take the range rather than a single number.
- People affected: MAG and most reporting say approximately 8.7 million (BBC, Computer Weekly, TechRadar, CTI Pilot). Security Affairs and SecurityWeek headline 8.8 million, sourced to HaveIBeenPwned's parse of the dump, which found roughly 8.8 million email addresses and phone numbers. SecurityWeek carries both figures in the same article: 8.7 million per FulcrumSec's own claim, 8.8 million per HIBP.
- Data volume: FulcrumSec initially told BleepingComputer it held approximately 86 GB. At publication it described the release as "half a terabyte," and SecurityWeek puts the published set at roughly 550 GB uncompressed. The gap is most plausibly compressed-versus-uncompressed accounting, but no source confirms that, and the two numbers came from the same actor eight days apart.
- Field types: MAG acknowledged email addresses, phone numbers, vehicle registrations and postcodes, and said the compromised system held no bank or payment-card data. Computer Weekly's review of the dataset adds browser user agents, IP addresses, geolocation, purchase histories and names. CTI Pilot, citing The Register, notes that the overwhelming majority of those affected had only an email address exposed, harvested at public WiFi signup, with a smaller subset exposed across the richer fields.
- Discrete counts claimed by FulcrumSec: 2,482,763 purchases, 461,433 booking-related SMS messages and 108,077 unique UK vehicle registration plates.
- High-value records: FulcrumSec claims to hold data on celebrities, journalists, MPs, sporting figures and more than 11,000 NHS workers.
Where Accounts Differ
The most consequential disagreement in this incident concerns the roughly 200,000 records covering passengers' upcoming travel for the remainder of 2026.
FulcrumSec publicly stated it withheld that tranche, calling it "the most dangerous part of the breach" and arguing that upcoming schedules linked to full PII and vehicle data create "an ideal opportunity for burglars, stalkers, and worse." That claim is carried by Computer Weekly and Security Affairs, and BleepingComputer reported on 30 August that the group was already weighing withholding or redacting those records.
That does not square cleanly with what analysts found in the published files. Computer Weekly reports the leak exposed the vehicle registration numbers of at least three individuals working in the UK judicial system who had booked parking at MAG sites in the coming weeks. The Mail on Sunday reports finding the vehicle registration and upcoming travel plans of a Bank of England official, and the number plate and future travel details of a Home Office employee, in the released data.
Read the withholding claim as an extortion posture, not a verified fact. Forward-dated bookings are demonstrably present in the leak in at least some cases. Treat the 200,000-record figure as an unverified actor claim, and assume any record in the dump may carry a future date.
Why It Matters
This is a low-sophistication compromise of a low-sensitivity-looking dataset that produced a high-sensitivity outcome, and that is the lesson defenders should carry away.
Nobody classifies airport WiFi signup logs or car park bookings as crown-jewel data. But joined together, they resolve to a name, a home postcode, a licence plate, a phone number and a timestamped absence from home. For a circuit judge, a Home Office official or an Armed Forces member, the combination of a plate and a departure date is a physical-security problem, not a privacy problem. FulcrumSec's own framing of burglary and stalking risk is self-serving, but it is not wrong about the exposure.
The judiciary and government-worker angle rests principally on The Mail on Sunday's analysis of the dump, an OTHER-tier source, though Computer Weekly independently corroborates the presence of judicial-system vehicle registrations. Neither MAG nor any UK authority has confirmed a specific list of exposed officials in these sources.
The second-order risk is fraud quality. An attacker holding a victim's real booking reference, terminal, amounts paid and travel dates can construct a phishing pretext that no generic filter and few humans will catch. MAG urged customers to stay alert to suspicious emails, texts and calls and to avoid attachments from unknown senders; that guidance is correct but thin against this grade of targeting.
Finally, MAG refused to pay, in line with UK government and NCSC advice, and TechRadar notes the dump appears aimed in part at recouping value by selling access to other criminals. Refusal is the right policy and it does not prevent publication. Plan for the leak, not for the negotiation.
The Attack Technique
FulcrumSec's stated access vector is a client-side credential exposure. The group told BleepingComputer it obtained airport-specific Iterable API credentials embedded in client-side JavaScript, and stated on its leak site that Iterable admin keys were hardcoded into the frontend JavaScript of all three airport websites, manchesterairport.co.uk, stanstedairport.com and eastmidlandsairport.com, each with its own key granting access to millions of passenger records. It described the method as "so simple it is tragi-comical."
This is an actor claim. MAG has not publicly confirmed the vector in any source here, but it is corroborated across BleepingComputer, Security Affairs, SecurityWeek and CTI Pilot, and it is consistent with what MAG did confirm: SecurityWeek reports MAG acknowledged the stolen information was held in a third-party-hosted database. Iterable is a marketing engagement platform, which fits both the data types (WiFi signups, marketing classifications, booking-linked SMS) and the presence of a roughly 21.5 GB consolidated Manchester customer export combining identifiers, historical bookings and marketing segments, as reviewed by BleepingComputer.
CTI Pilot, attributing to The Register rather than to MAG, reports that the intrusion compromised one internal system before pulling files from the third-party database, that the ransom demand was notably lower than the group's usual, and that MAG characterises the incident internally as "a hack, not a lapse." That internal characterisation sits awkwardly beside a hardcoded-key vector. Accounts of how much of this was intrusion versus exposure are not reconciled in public reporting.
FulcrumSec also said it intends to publish a technical account of the intrusion. Defenders should watch for it, and treat it as adversary marketing when it lands.
What Organizations Should Do
- Audit every shipped frontend bundle for credentials, today. Grep production JavaScript, source maps and mobile app bundles for API keys, admin tokens and SaaS credentials. Anything in client-side code is public. Wire this into CI as a blocking secret scan, not a periodic review, and cover per-brand or per-property builds separately, since three sites here each carried their own key.
- Scope every marketing and engagement SaaS integration to least privilege. Iterable-class platforms accumulate the full customer graph. Replace admin-tier keys with narrowly scoped, server-side-only tokens, put a backend proxy between the browser and the vendor, enforce per-key rate limits and IP allowlists, and rotate on a schedule. Ask each vendor what a single leaked key can enumerate.
- Treat third-party-hosted customer databases as in-scope for your own detection. MAG's confirmed loss was from a database it did not host. Ensure you receive and monitor vendor-side API logs, and alert on bulk export or anomalous enumeration volume rather than relying on the vendor to notice.
- Reclassify aggregated low-sensitivity data by what it enables. Run the join yourself: plate plus postcode plus forward booking date equals a physical-security disclosure. Apply retention limits to WiFi signup logs and completed bookings, and separate forward-dated travel records into a higher-protection store with tighter access controls.
- Build a VIP and at-risk-cohort exposure playbook before you need it. Judiciary, government, military, healthcare and public-figure records will be in consumer datasets you did not think of as sensitive. Define in advance how you identify them post-incident, who you notify (including employers and protective-security teams), and what mitigations you can offer, such as escorted parking or booking cancellation.
- Assume publication and pre-brief your customer communications. Refusing to pay is correct and guarantees a dump. Prepare targeted notification for the high-detail subset, not just a blanket email, and warn explicitly that fraudsters may quote genuine booking references, terminals and amounts paid. MAG says it reached out specifically to those with upcoming bookings; that is the right shape of response.
- If you are an affected traveller with a forward booking: treat any unsolicited contact quoting your booking details as hostile until verified through the airport's own channels, and consider whether a publicly known departure date warrants adjusting home-security arrangements.
Sources: Airport hackers publish personal data of judge, politicians and cel... | Hackers steal data from millions of UK airport customers - BBC News | UK airport hackers leak stolen customer data Computer Weekly | FulcrumSec claims Manchester Airports hack, theft of 86 GB of data | Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Mil... | Manchester Airports Group Data on 8.8 Million People Leaked After R... | Manchester Airports hackers post data of 8.7m people TechRadar | Manchester Airports Group confirms a breach touching roughly 8.7 mi...