Skip to content
Manchester Airports Group Breach: FulcrumSec Publishes Alleged Stolen Data

Manchester Airports Group Breach: FulcrumSec Publishes Alleged Stolen Data

Technadu September 2, 2026

Breach confirmed: MAG confirmed unauthorized access to customer information affecting Manchester, London Stansted, and East Midlands airports.

8+ million customers: Threat actor FulcrumSec claims the incident exposed approximately 8.67 million customer profiles.

API key claim: FulcrumSec says exposed Iterable API credentials in frontend JavaScript provided access to the data.

FulcrumSec published an alleged Manchester Airports Group (MAG) data breach, listing customer profiles, purchase records, future travel plans, and marketing event details. MAG only confirmed a cybersecurity incident involving unauthorized access to customer information connected to Manchester Airport, London Stansted Airport, and East Midlands Airport.

FulcrumSec Claims Exposed Iterable API Credentials

FulcrumSec claims it gained access through Iterable API credentials embedded in client-side JavaScript used by the airport websites. According to the group, those credentials allowed access to MAG's marketing environment and enabled the extraction of customer information.

The hackers claim the stolen material, which reportedly totals around 86 GB, includes:

8.67 million customer profiles,

2.48 million purchase records

1.16 billion marketing events.

access to SMS information

108,000 vehicle registrations.

The allegation is significant from a security perspective because credentials embedded in browser-delivered JavaScript can be inspected by users. However, MAG has not publicly confirmed the alleged API -key attack path.

Future Travel Data Allegedly Exposed

FulcrumSec further claims that around 190,000 upcoming bookings were included in the stolen information, with more than 142,000 records allegedly linking passenger email addresses to vehicle registrations:

booking and purchase history,

vehicle registrations,

platform configuration data

Independent validation of a sample record against a real traveller's purchase history reportedly found matching Fast Track booking details, arrival information, terminal, and payment amounts. Yet, this does not establish the full scope of the alleged 86 GB dataset.

MAG Says Passenger and Aviation Security Were Not Affected

MAG said the incident affected information associated with airport parking, lounge and Fast Track bookings, as well as on-airport Wi-Fi sign-ups. The company said the overwhelming majority of affected customers had only their email addresses compromised, while a smaller subset also had phone numbers, vehicle registration numbers and postcodes exposed.

MAG has said passenger safety and aviation security were not compromised and that it has contacted affected customers, including customers with upcoming bookings. The company has also said it is working with relevant authorities and investigating the incident.

FulcrumSec is a financially motivated data-extortion group active since 2025 that steals sensitive corporate data and threatens to publish it rather than encrypting victims' systems; it has previously claimed an attack on Novo Nordisk .