FulcrumSec Breaches Manchester Airports, Steals 86 GB of Data

A major data breach at Manchester Airports Group exposes 86 GB of customer data, including future travel records, through exposed API credentials in client-side code.

By Central
The breach of Manchester, Stansted, and East Midlands airports reveals vulnerabilities in cloud marketing platforms.
Highlights
  • FulcrumSec stole 86 GB of data from Manchester Airports Group using exposed Iterable API credentials in client-side JavaScript.
  • Nearly 200,000 records of future travel in 2026 were allegedly exposed, raising concerns about aviation data security.
  • The breach captured detailed traveler behavior data, including booking history, timestamps, and marketing classifications.

The scale of data breaches affecting critical infrastructure continues to escalate, and the recent compromise of Manchester Airports Group (MAG) by the extortion group FulcrumSec represents one of the most significant security incidents to hit a British airport operator. With approximately 86 gigabytes of data stolen and nearly 200,000 records of future travel in 2026 allegedly exposed, the breach raises urgent questions about how airport operators secure customer data and what happens when cloud-based marketing platforms become the weak link in aviation security.

What FulcrumSec Stole From Manchester, Stansted, and East Midlands Airports

FulcrumSec, a financially motivated data-extortion group active since 2025, has claimed responsibility for the theft of customer data from MAG, which operates Manchester Airport, London Stansted Airport, and East Midlands Airport. The group told BleepingComputer that it stole approximately 86 GB of data, with samples reviewed by the publication confirming that the breach exposed considerably more detailed customer, booking, and travel information than MAG initially disclosed.

MAG disclosed on August 27 that an unauthorized third party had stolen customer data related to car park, lounge, and Fast Track bookings, as well as in-airport Wi-Fi registrations. However, the sampled records reviewed by BleepingComputer contained purchase and booking references, airport and product selections, prices, discounts, booking status, parking dates and times, historical spending, IP addresses, approximate locations, device information, and customer-engagement data. Beyond the email addresses, phone numbers, vehicle registrations, and postcodes that MAG acknowledged, the breach appears to have captured a much richer portrait of traveler behavior.

BleepingComputer validated one record by comparing it with the traveller’s known Manchester Airport purchase history. The record accurately listed previous Fast Track purchases, booking and scheduled-arrival times, the terminal used, amounts paid, purchase references, total spending, and the apparent purpose of the trips. This level of detail suggests that FulcrumSec accessed consolidated marketing and customer-relationship management profiles, not merely isolated transaction logs.

One approximately 21.5 GB Manchester customer export contained consolidated profiles that combined customer identifiers with historical booking activity and marketing classifications. The group claims it obtained access using airport-specific Iterable API credentials exposed in client-side JavaScript, pointing to a vulnerability in how MAG integrated its marketing automation platform with its public-facing web applications.

How the Attack Worked: Exposed API Credentials in Client-Side Code

FulcrumSec claims that the intrusion began with airport-specific Iterable API credentials that were exposed in client-side JavaScript. Iterable is a customer-engagement and marketing automation platform widely used by organizations to manage email campaigns, push notifications, and in-app messaging. When API keys or tokens are embedded directly in JavaScript code that runs in the user’s browser, they become visible to anyone who inspects the page source or network traffic.

This class of vulnerability is well-documented and preventable. Security teams typically store sensitive credentials in server-side environment variables or use secure token-exchange protocols rather than embedding them in front-end code. The exposure suggests that MAG’s implementation of the Iterable platform did not follow industry best practices for credential management, potentially because the integration was treated as low-risk marketing infrastructure rather than a system handling sensitive customer data.

Once FulcrumSec obtained valid API credentials, the group could query MAG’s Iterable environment to extract customer profiles, booking histories, and marketing classifications. The attackers did not need to breach MAG’s core airport operations systems, payment processors, or flight management tools. They exploited a single weak point in the customer-engagement technology stack to exfiltrate data on millions of travelers.

Nearly 200,000 Records of Future Travel in 2026

One of the most concerning elements of the breach is FulcrumSec’s claim that the stolen material includes nearly 200,000 records related to upcoming travel during the remainder of 2026. These records allegedly contain dates, times, and booking information linked to personally identifiable information. If accurate, this means that travelers who have not yet taken their booked flights have had their future plans exposed to an extortion group that has already demonstrated a willingness to publish stolen data.

FulcrumSec told BleepingComputer that it intends to publish the stolen data and a technical account of the intrusion but is considering withholding or redacting those records because of the potential for real-world harm. This statement represents a rare acknowledgment from a threat actor that certain data categories cross a threshold that even they consider dangerous. It also raises the possibility that the group may use the threat of publishing future-travel data as additional leverage in ransom negotiations.

BleepingComputer could not independently verify the alleged source or extent of the threat actor’s access, the overall size of the stolen dataset, or the claim concerning nearly 200,000 upcoming-travel records. However, the validated sample records lend credibility to FulcrumSec’s overall narrative about the scope of the compromise.

MAG’s Response: Contacting Affected Customers but Declining to Address Specific Claims

MAG has confirmed that an unauthorized third party stole customer data and has contacted affected customers with upcoming bookings to advise them of additional support. A spokesperson declined to address FulcrumSec’s specific claims concerning the 86 GB dataset, exposed credentials, and future-travel data, referring instead to updated statements that confirmed outreach to affected travelers.

MAG is confident that it has taken effective measures to protect customers and has contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support. The airport operator stressed that it would never contact customers unexpectedly to request payment-card details, banking information, or passwords. The attackers reportedly demanded a monetary ransom, which MAG was understood to have refused to pay.

The incident has not caused operational disruption, and MAG says passenger safety and aviation security were not compromised. A MAG spokesperson previously told the Manchester Evening News that approximately 8.7 million customers were affected, although only email addresses were exposed for the vast majority. That makes it the largest known customer data breach affecting a British airport operator.

What the Exposed Data Means for Travelers: Phishing and Social Engineering Risks

The specific combination of data types exposed in this breach creates unusually high risks for targeted social engineering attacks. Unlike US ZIP codes, which generally cover broader delivery areas, a full UK postcode can identify a small group of neighboring properties. According to the UK Office for National Statistics, a typical small-user postcode covers approximately 15 addresses, while some postcodes are assigned to a single address.

Combined with contact information, vehicle registration details, travel dates, parking locations, and purchased services, these postcodes enable attackers to craft highly convincing phishing emails, text messages, or telephone calls that impersonate MAG or a booking provider. A victim who receives a message referencing their specific airport, parking dates, booking status, and partial postcode is far more likely to trust the communication and comply with requests for payment details or login credentials.

MAG has advised affected customers to remain vigilant for suspicious emails, text messages, and telephone calls. The company emphasized that it would never contact customers unexpectedly to request payment-card details, banking information, or passwords. Travelers who have used Manchester, Stansted, or East Midlands airports should be especially cautious about any unsolicited communications that reference their booking details, even if the information appears accurate.

FulcrumSec: A New Wave of Data-Extortion Groups

FulcrumSec is a financially motivated data-extortion group active since 2025 that focuses on stealing sensitive corporate data and threatening to publish it rather than encrypting victims’ systems. This model, sometimes called leak extortion or data theft without ransomware, has become increasingly common as organizations improve their backup and recovery capabilities and become more reluctant to pay for decryption keys.

The group has previously claimed attacks on organizations including LexisNexis, Novo Nordisk, Global Schools Group, and Avnet. These targets span legal information services, pharmaceutical manufacturing, international education, and electronics distribution, suggesting that FulcrumSec does not specialize in a single sector but instead pursues organizations where stolen data can be monetized or used to pressure victims into paying ransoms.

FulcrumSec’s operational methodology appears to prioritize reconnaissance of cloud-based marketing and customer-engagement platforms. By targeting integrations between web applications and third-party services like Iterable, the group can compromise substantial datasets without needing to breach hardened core infrastructure. This approach lowers the technical bar for successful attacks while maximizing potential impact.

Why Airport Customer Data Is a High-Value Target

Airports collect and retain extensive customer data because their operations depend on managing millions of passenger journeys, parking reservations, lounge access, and Fast Track bookings. This data accumulates over years of travel history, creating consolidated profiles that are valuable for marketing analytics but also represent a rich target for data thieves.

The combination of personally identifiable information, travel patterns, vehicle details, and payment transaction references allows attackers to construct detailed behavioral profiles. Unlike a credit card number, which can be reissued, or a password, which can be changed, a person’s travel history and future bookings are difficult to reset. Once exposed, this information can be used for targeted scams indefinitely.

The breach also highlights a broader industry challenge: customer-engagement platforms and marketing automation tools often handle sensitive data but may not receive the same security scrutiny as core operational systems. When API credentials for these platforms are exposed, the downstream consequences can rival or exceed those of a direct breach of the primary database.

Best Practices for Data Security in Aviation Customer Platforms

The MAG breach offers several lessons for organizations that manage customer data through third-party marketing platforms. First, API credentials must never be embedded in client-side code. Organizations should use server-side proxies, token-exchange mechanisms, or secure credential stores to protect access to customer-engagement platforms.

Second, the scope of data accessible through marketing automation tools should be reviewed and minimized. If the Iterable integration at MAG had been limited to basic contact information and campaign engagement metrics, the exposure would have been far less severe. Instead, the platform appears to have had access to detailed historical booking data, spending history, and marketing classifications.

Third, incident response plans should account for the possibility that a breach of a marketing or engagement platform may expose data that is broader than what the organization initially recognizes. MAG’s initial disclosure described car park, lounge, Fast Track, and Wi-Fi data, but the actual exposure appears to have included considerably more detailed travel and personal information.

Fourth, organizations should consider segmenting customer data based on risk and sensitivity. Future-travel records, in particular, represent a category of data that, if exposed, creates immediate physical safety and fraud concerns that differ from the exposure of historical transaction data.

The Larger Landscape: Data Breaches in the Aviation Sector

This incident is not an isolated event. The aviation sector has been a frequent target for cyberattacks, with threat actors recognizing that airports and airlines hold vast quantities of passenger data and operate complex technology ecosystems where security gaps are common. The sensitivity of travel data, combined with the operational criticality of airport systems, makes the sector an attractive target for both extortion and espionage.

Previous incidents have included ransomware attacks that disrupted flight operations, data breaches that exposed frequent-flyer accounts, and supply-chain compromises that affected multiple airlines simultaneously. The MAG breach is notable because it did not disrupt airport operations but still managed to compromise data on millions of passengers, demonstrating that the absence of operational impact does not mean the absence of serious harm.

Regulatory scrutiny is likely to intensify. The UK Information Commissioner’s Office and the Civil Aviation Authority are expected to investigate the breach, and organizations that fail to secure customer data through common integration points may face significant fines and reputational damage.

How Travelers Can Protect Themselves After the MAG Breach

Travelers who have used Manchester, Stansted, or East Midlands airports should assume that their contact information, vehicle registration, and booking history may have been compromised. The first step is to be extremely cautious about any unsolicited communications that reference airport bookings, parking details, or travel dates.

Legitimate organizations, including MAG, will not ask for payment-card details, banking information, or passwords through unsolicited email or text messages. Any communication that requests such information or directs the recipient to a login page should be treated as suspicious. Travelers should navigate directly to official websites rather than clicking links in messages.

Those who have upcoming bookings should monitor their accounts for unauthorized access attempts and consider enabling multi-factor authentication on any accounts associated with airport services or travel bookings. If the same password has been used across multiple travel-related sites, it should be changed immediately.

Credit monitoring services are unlikely to detect the type of identity theft that could result from this breach, as the stolen data is more suited to targeted phishing and social engineering than direct financial fraud. However, travelers should remain alert for unusual activity related to their vehicle registration, travel history, or airport accounts.

The exposure of nearly 200,000 future-travel records, if confirmed, adds a particularly concerning dimension. Anyone with upcoming bookings at MAG airports should verify the status of their reservations directly through official channels and be wary of any communications that attempt to modify or confirm travel details using information that could only have come from the breached systems.

The FulcrumSec attack on Manchester Airports Group represents a significant escalation in the targeting of aviation customer data through marketing and engagement platforms. With 86 GB of data stolen, approximately 8.7 million customers affected, and future-travel records potentially exposed, the breach serves as a stark reminder that the security of customer data depends not only on protecting core databases but also on rigorously securing every integration point where that data flows. Until airport operators and their technology partners implement credential management practices that match the sensitivity of the information they hold, travelers remain vulnerable to attacks that exploit the very systems designed to improve their journey experience.

Share This Article