Back Infosecurity-Magazine FulcrumSec Claims Responsibility for Manchester Airport Group Breach
A threat group claiming responsibility for a breach of the UK’s largest airport group appears to have leaked almost all of the 550GB of data it stole online.
FulcrumSec posted the data for download on its leak site, claiming to have around 549GB of uncompressed data on MAG customers which it said was “pure PII.”
If the group’s claims are correct, the post sheds more light on the incident, which to date there has been limited information on.
It claimed that initial access was made possible after it found admin keys for customer engagement platform Iterable in the frontend JavaScript of each of the three airport’s websites.
“These keys were not found on some obscure subdomain, as was the case with the credentials that led to our breaches of Arup Group and Novo Nordisk. All three of these were on the sites’ root domain,” the note explained.
“No subdomain enumeration or URL crawling necessary; any of the millions of visitors to the site could have right-clicked ‘inspect’ and seen the keys just sitting there, plain as day. On all three websites.”
MAG manages Manchester Airport, Stansted Airport and East Midlands Airport.
The FulcrumSec post also claimed that the group obtained a much broader sweep of customer information than at first revealed by MAG.
It said it exfiltrated nearly 8.7 million customer profiles, including email, name, mobile number, town, postcode and residential IP address. That could enable convincing follow-on phishing attacks on victims.
Also swept up in the data breach were allegedly:
Nearly 1.2 billion marketing events including sends, opens and clicks
Nearly 2.5 million purchases – every booking that customers of parking, Fast Track and lounges have ever made
Over 461,000 SMS messages with passenger booking date, car park and vehicle reg in plain text
108,000 unique vehicle registration plates
Platform configuration data
Physical Danger for Travellers
FulcrumSec also claimed to have data on nearly 191,000 future bookings, which includes travel schedules, PII and vehicle information that could be used by criminals to physically target holidaymakers’ homes.
It said that some of these individuals were likely public figures, politicians and military staff, judging by the email addresses associated with the bookings.
“Sadly MAG declined to pay the necessary fee to protect their passengers’ data, leaving us to remove the most sensitive parts … from the leak prior to publication,” the group added.
The group's claims have yet to be fully verified and MAG has not provided any update since its original post on August 27.
API Attacker Steals Data on 37 Million T-Mobile Customers News 20 January 2023
API Attacker Steals Data on 37 Million T-Mobile Customers
How Web Applications Can Support Overall Security -Gen 11 May 2020
How Web Applications Can Support Overall Security
Stolen Cloud API Key to Blame for Imperva Breach News 14 October 2019
Stolen Cloud API Key to Blame for Imperva Breach
Quarter of Firms Suffer an API-Related Breach News 18 June 2024
Quarter of Firms Suffer an API-Related Breach
What Telcos Should Learn from the Optus Breach Opinion 29 September 2022
What Telcos Should Learn from the Optus Breach
What’s Hot on Infosecurity Magazine?
Cybersecurity Job Ads Requiring AI Skills Double
Healthcare Giant McKesson Investigates Data Breach Incident
Average Cyber Insurance Losses Increase Despite Fewer Claims
Manchester Airports Group Hit by Cyber Incident
Attackers Steal METR API Key and Burn $600,000 in AI Credits
65% of Enterprises Have Seen AI Agents Act Out of Scope
DDoS Attack Hits Norwegian Government Services
Manchester Airports Group Hit by Cyber Incident
Linux Foundation Introduces TRACE Standard for AI Runtime Evidence
Average Cyber Insurance Losses Increase Despite Fewer Claims
Agentic AI will Supercharge Cyber Threats. But Not in the Way You Think
Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
How To Enhance Security Operations with AI-Powered Defenses
Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Dispelling the Myths of Defense-Grade Cybersecurity
Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
