Breaking
SecurityDeveloping Story

FulcrumSec Claims Manchester Airport Breach, 86 GB Stolen

Extortion group FulcrumSec says it stole 86 GB from Manchester Airports Group, exposing detailed travel data.

··2 hours ago·4 min read
building interior photograph
Photo by Nick Fewings on Unsplash

In a claim that has put UK airport security under renewed scrutiny, the extortion group FulcrumSec says it is responsible for the Manchester Airports Group data breach, asserting that it stole approximately 86 GB of data. The group provided samples to BleepingComputer that appear to show far more intimate travel and booking details than the airport operator initially acknowledged.

Group Claims Theft of 86 GB

Manchester Airports Group (MAG), the UK's largest airport operator, disclosed on August 27 that an unauthorized third party had stolen customer data related to Manchester, London Stansted, and East Midlands airports. The company said the affected information came from car park, lounge, and Fast Track bookings and in-airport Wi-Fi registrations.

In emails to BleepingComputer, FulcrumSec claimed responsibility for the attack and shared samples of the allegedly stolen data as evidence. BleepingComputer validated one record by comparing it with the traveller's known Manchester Airport purchase history. The record accurately listed previous Fast Track purchases, booking and scheduled-arrival times, the terminal used, amounts paid, purchase references, total spending, and the apparent purpose of the trips.

Detailed Travel Data in Samples

The material included a roughly 21.5 GB Manchester customer export containing consolidated profiles that combined customer identifiers with historical booking activity and marketing classifications. That volume alone suggests the scope of exposure is broader than the email addresses, phone numbers, vehicle registrations, and postcodes initially disclosed.

Sampled records contained purchase and booking references, airport and product selections, prices, discounts, booking status, parking dates and times, historical spending, IP addresses, approximate locations, device information, and customer-engagement data. BleepingComputer did not observe payment-card or bank-account information in the reviewed samples.

Credentials in Client-Side Code

The group claims it obtained access using airport-specific Iterable API credentials exposed in client-side JavaScript. Iterable is a customer engagement platform, and the credentials would have been visible to anyone inspecting the web page's code. That technique, known as client-side exposure, lets attackers harvest keys that are mistakenly left in browser-facing scripts.

FulcrumSec says it intends to publish the stolen data and a technical account of the intrusion. However, it told BleepingComputer that it is considering withholding or redacting those records because of the potential for "real-world harm." The reference appears to acknowledge that the data could be used for targeted scams.

Upcoming Travel Records at Risk

The group says the stolen material includes nearly 200,000 records related to upcoming travel during the remainder of 2026. These records allegedly contain dates, times, and booking information linked to personally identifiable information. If accurate, that data would let attackers craft highly specific phishing messages, referencing actual travel plans.

While the samples appeared authentic, BleepingComputer could not independently verify the alleged source or extent of the threat actor's access, the overall size of the stolen dataset, or the claim concerning nearly 200,000 upcoming-travel records. After completing its verification, BleepingComputer securely deleted all supplied material without retaining copies and will not publish or share any part of it.

FulcrumSec's Known Attacks

FulcrumSec is a financially motivated data-extortion group active since 2025 that focuses on stealing sensitive corporate data and threatening to publish it rather than encrypting victims' systems. The group has previously claimed attacks on organizations including LexisNexis, Novo Nordisk, Global Schools Group, and Avnet. Its modus operandi is to demand payment to prevent the release of stolen information.

The attackers reportedly demanded a monetary ransom, which MAG was understood to have refused to pay. MAG declines to address the extortion claim.

MAG Spokesperson Response

BleepingComputer contacted MAG again before publication and asked the company to address FulcrumSec's claims concerning the 86 GB dataset, exposed credentials, and future-travel data. A spokesperson declined to address the specific claims, referring instead to an updated statement confirming that affected customers with upcoming bookings had been contacted.

"MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support," a MAG spokesperson told BleepingComputer.

The company has advised affected customers to remain vigilant for suspicious emails, text messages, and telephone calls. MAG stressed that it would never contact customers unexpectedly to request payment-card details, banking information, or passwords.

Postcode Exposure and Phishing Risk

Unlike US ZIP codes, which generally cover broader delivery areas, a full UK postcode can identify a small group of neighboring properties. According to the UK Office for National Statistics, a typical small-user postcode covers approximately 15 addresses, while some postcodes are assigned to a single address. Combined with contact, vehicle, and travel information, these details could allow attackers to reference a victim's airport, vehicle, parking dates, booking status, or purchased services in convincing phishing emails, text messages, or telephone scams impersonating MAG or a booking provider.

The incident has not caused operational disruption, and MAG says passenger safety and aviation security were not compromised. A MAG spokesperson previously told the Manchester Evening News that around 8.7 million customers were affected, although only email addresses were exposed for the "vast majority." That makes it the largest known customer data breach affecting a British airport operator.

Why This Matters

If the stolen data includes detailed booking and travel history, the risk to affected travelers extends beyond spam. Attackers could use the information to craft personalized scams that reference real airport visits, parking durations, or upcoming trips, making phishing attempts harder to spot. For MAG, the refusal to pay and the public disclosure of the incident may help mitigate immediate harm, but the long-term impact of a breach affecting millions of customers, especially if the alleged 86 GB dataset includes non-public records, could erode traveler trust in the airport's data handling practices. The case also underscores that client-side credentials are a persistent weak point, and that even a single exposed API key can lead to a large-scale data compromise.

#fulcrumsec#data breach#manchester airports#airport security#phishing

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories