Breaking
Cyber CrimeDeveloping Story

Ransom Refusal Exposes 8.8M in Airport Breach

Manchester Airports Group data leak exposes 8.8M records after refusing ransom.

··2 hours ago·3 min read
grayscale photo of airplane
Photo by Rhiannon Elliott on Unsplash

When Manchester Airports Group (MAG) refused to pay a ransom demand, it likely expected some fallout. But the scale of what followed became clear this week as the FulcrumSec extortion gang published a massive cache of allegedly stolen data, affecting millions of individuals across three UK airports.

According to data breach notification site HaveIBeenPwned, which parsed the leaked dataset and integrated it into its database, approximately 8.8 million email addresses and phone numbers were compromised. The leaked information also includes names, browser agent details, purchases, and vehicle registration plates.

Airport Operator Confirms Breach

MAG disclosed the incident last week, warning that hackers had breached its systems and stolen data related to car park bookings, lounge access, and Fast Track services. The breach also affected in-airport Wi-Fi sign-ups at Manchester, London Stansted, and East Midlands airports.

The airport operator revealed that the attackers exfiltrated email addresses, phone numbers, vehicle registrations, and postcodes. However, MAG emphasized that its operations were not affected by the incident. The stolen information was stored in a database hosted by a third party, and MAG confirmed receiving a ransom demand but refrained from sharing further details.

FulcrumSec Claims Responsibility

Over the weekend, the FulcrumSec extortion gang claimed responsibility for the attack. Since then, the group has published roughly 550 gigabytes of uncompressed data allegedly stolen from MAG. The group says the data includes personal information of approximately 8.7 million individuals, encompassing names, emails, phone numbers, town and postal region, and residential IP addresses used to access accounts.

FulcrumSec admitted that MAG did not pay a ransom. SecurityWeek has not independently verified the attackers' claims.

Exposed Data Details

Beyond the email and phone numbers, FulcrumSec claims the stolen data includes 2,482,763 purchases (bookings for parking, lounge, and fast-track products), 461,433 SMS messages associated with bookings, car park, and vehicle registration, and 108,077 unique UK vehicle registration plates.

  • 8.8 million email addresses and phone numbers compromised
  • 550 gigabytes of uncompressed data leaked
  • 2,482,763 purchases exposed
  • 461,433 SMS messages associated with bookings
  • 108,077 unique UK vehicle registration plates

Admin Keys in Plain Sight

FulcrumSec says it breached MAG's systems using admin keys that were left in plain sight “in the frontend JavaScript of each of its three airports’ websites,” in each root domain. This suggests a significant oversight in MAG's web security, as such keys should never be exposed client-side.

The extortion group has admitted that MAG did not pay a ransom, which may have prompted the full release of the stolen data. The data leak serves as a cautionary tale about the risks of storing sensitive information in third-party databases without proper security measures.

Impact on Affected Individuals

For the millions of individuals whose data is now public, the risks are substantial. Exposed email addresses and phone numbers can be used for phishing campaigns, spam, and social engineering attacks. Vehicle registration plates could potentially be used for cloning or other fraudulent activities. The inclusion of residential IP addresses adds another layer of privacy intrusion.

SecurityWeek has not independently verified the attackers' claims, but the HaveIBeenPwned integration suggests that the dataset is legitimate. Individuals who may have used MAG's services at the affected airports should monitor their accounts and be wary of unsolicited communications.

Broader Implications for Airport Security

This incident highlights the importance of securing third-party databases and ensuring that administrative credentials are not exposed in client-side code. Airports, which handle vast amounts of personal data from travelers, are prime targets for cybercriminals. The refusal to pay the ransom may have been a principled stance, but it resulted in a massive data dump that could have long-lasting consequences for affected individuals.

As FulcrumSec continues to leak data, the focus now shifts to how MAG and affected individuals respond. The breach serves as a reminder that ransomware attacks are not just about encryption but also about data theft and extortion. Organizations must implement robust security measures, including regular audits, to prevent such exposures.

Why It Matters

This breach underscores the growing threat of extortion-based cyberattacks, where refusing to pay can lead to the public release of sensitive data. For the millions of people affected, this means an increased risk of identity theft and fraud. It also raises questions about the security practices of third-party vendors and the need for stronger regulatory oversight. As airports and other critical infrastructure become more digitized, the stakes for protecting personal data have never been higher.

#manchester airports group#data breach#fulcrumsec#ransomware#cybersecurity#airport security

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories