The customer data breach at Manchester Airports Group turns out to be considerably larger and more operationally dangerous than the company’s initial disclosure suggested — and it was opened by an entry point that required no hacking at all. Extortion group FulcrumSec told BleepingComputer it pulled approximately 86 gigabytes of customer data from MAG’s Iterable marketing platform using API credentials the airport operator had left embedded in publicly visible JavaScript code: the kind of exposure any visitor with a browser and developer tools could read without logging in, exploiting a vulnerability, or generating the sort of network anomaly that intrusion-detection systems are built to catch. BleepingComputer reported the group’s claims on August 30, 2026, the day FulcrumSec contacted the publication with data samples.
Among the alleged stolen material: roughly 200,000 records tied to upcoming travel through the remainder of 2026, complete with passenger names, dates and times, terminals, booking references, vehicle registrations, and UK postcodes. Because a UK postcode covers 15 addresses on average — sometimes a single property — that combination is effectively a home address plus a travel schedule for each of those 200,000 travelers. The data is not a contact list. It is a precision-targeted fraud asset.
What MAG Disclosed — and What It Left Out
Manchester Airports Group — the UK’s largest airport operator, generating annual revenue of approximately £1.5 billion (roughly $2.03 billion USD) and running Manchester, London Stansted, and East Midlands airports — disclosed the breach publicly on August 27, 2026, three days after detecting unauthorized access.
The company confirmed that an unauthorized third party obtained customer data tied to car park, lounge, and Fast Track booking systems, as well as in-airport Wi-Fi registrations across all three airports, affecting approximately 8.7 million customers. The majority had only email addresses exposed. Customers who had used parking, lounge, or Fast Track services faced broader exposure including phone numbers, vehicle registration plates, and postcodes. No payment card or banking information was stored in the affected systems, MAG said.
MAG notified law enforcement, the National Cyber Security Centre, and the Information Commissioner’s Office. It said the incident involved one internal system before pivoting to a database hosted by an unnamed third party. That unnamed third party, per FulcrumSec’s claims to BleepingComputer, was Iterable.
What the disclosure did not address: how the attacker got in, how much data was actually taken, and whether future travel plans were among the exposed records.
How FulcrumSec Says It Got In: A Credential Left in Plain Sight
FulcrumSec’s account of the entry point is both technically specific and strategically significant. The group told BleepingComputer that Iterable API credentials were left exposed in client-side JavaScript — meaning anyone who visited MAG’s web properties and opened a browser’s developer tools could read those credentials directly from the page source.
Iterable is a customer engagement and marketing automation platform. MAG used it for booking confirmation emails and Wi-Fi sign-up messages — precisely the systems whose customer behavioral data appears in FulcrumSec’s claimed export. The key insight here is that a marketing platform API key is not a low-privilege credential. Iterable needs access to complete customer behavioral profiles — booking histories, transaction records, personal identifiers, marketing classifications — specifically so it can send personalized communications. That same consolidated dataset is what FulcrumSec extracted.
Security practitioners have consistently described the risk: a credential compiled into a frontend JavaScript bundle is readable by any visitor to the site. According to a 2026 API key security analysis, the gap between discovery and exploitation for an exposed API key is measured in minutes, not days. Once inside a marketing platform with high-privilege API access, an attacker can pull full customer database exports without triggering the network-anomaly alerts that traditional intrusion detection systems depend on. The “breach” registers in logs as a legitimate API call made with a legitimately issued key.
What FulcrumSec Claims Was Taken
The group shared data samples with BleepingComputer, which independently validated one traveler’s record by comparing it with the traveler’s known Manchester Airport purchase history. That record accurately listed previous Fast Track purchases, booking and scheduled-arrival times, the terminal used, amounts paid, purchase references, total spending, and the apparent purpose of the trips — the kind of detail that makes a follow-on phishing message difficult to dismiss as generic.
The samples included a roughly 21.5-gigabyte Manchester customer export consolidating customer identifiers with historical booking activity and marketing classifications. Beyond the email addresses, phone numbers, vehicle registrations, and postcodes that MAG confirmed, FulcrumSec’s sampled records also contained purchase and booking references, airport and product selections, prices and discounts, booking status, parking dates and times, historical spending totals, IP addresses, approximate locations, device information, and customer-engagement data.
BleepingComputer could not independently verify the overall 86-gigabyte dataset size or the claim of nearly 200,000 upcoming-travel records. No payment card or bank account information appeared in the reviewed samples.
FulcrumSec has said it plans to publish the stolen data. It told BleepingComputer it is considering whether to withhold the upcoming-travel records specifically — a harm-reduction caveat consistent with the group’s conduct during its Novo Nordisk breach in June 2026, when it similarly pledged to keep certain sensitive patient records off public channels. MAG says it refused the attacker’s demand.
Who Is FulcrumSec, and Why Does Its Track Record Matter?
FulcrumSec has been active since approximately September 2025 and has claimed roughly 25 victims across 11 countries. Its operational model — which the group has internally described as “steal and squeeze” — avoids ransomware encryption entirely, focusing instead on exfiltration and threatened publication. The group focuses entirely on rapid cloud-platform exfiltration and threatens to publish or sell stolen data if demands are not met.
The reason FulcrumSec’s track record matters to MAG’s affected customers is that the group’s prior conduct tells us something specific about what happens next. When Novo Nordisk refused a $25 million extortion demand in June 2026 after FulcrumSec claimed to have stolen approximately 1.3 terabytes of clinical trial data, drug research, and internal AI models, the group published two successive caches of material — source code, molecular blueprints, AI models and datasets — on its dark-web leak site. FulcrumSec has told BleepingComputer that MAG appeared unwilling to pay.
Cybersecurity researcher Thomas Willkan of Lab-1 described FulcrumSec to Reuters as “usually quite legit in terms of both their capabilities and also their claims.”
FulcrumSec’s previously confirmed or claimed victims include Blavity (November 2025), Lena Health (January 2026), youX (February 2026, approximately 300 gigabytes, 444,000 borrowers), LexisNexis (February 2026, via an unpatched React Server Components vulnerability on AWS infrastructure), Avnet (February 2026, approximately 1.3 terabytes including financial models and customer data), Global Schools Group (Singapore, 2026), and Novo Nordisk (June 2026). Full details of the group’s known tactics and prior victims were documented by Sysdig threat researchers in June 2026.
Why Your Postcode Plus a Parking Date Is More Dangerous Than a Card Number
MAG’s disclosure emphasized what was not exposed: no payment card details, no banking information. That framing, while accurate on its own terms, obscures what the exposed data enables.
Raghu Nandakumara, VP of industry strategy at Illumio, described the risk in concrete terms after the initial MAG disclosure: “The exposed data increases the risk of targeted phishing and smishing attempts, where attackers can use legitimate travel-related information to make malicious communications appear convincing.”
Payment card numbers can be canceled and reissued. A vehicle registration plate, a UK postcode, a parking date, a terminal, and a booking reference cannot be rotated. A criminal who contacts someone with specific knowledge of their actual upcoming trip — the terminal, the parking slot they booked, the Fast Track lane they paid for — is operating with a level of credibility that most generic phishing cannot replicate.
UK postcodes intensify this risk considerably. Unlike US ZIP codes, which can cover large delivery areas, UK postcodes typically identify approximately 15 neighboring addresses, with some assigned to a single property. A postcode combined with a vehicle registration and a parking date is not a contact record. It is, in practical terms, a home address and a schedule of when that address will be unoccupied.
Both MAG and security advisers have urged affected customers to treat any email, text message, or phone call referencing airport bookings with heightened suspicion — particularly messages that demonstrate knowledge of specific booking details — and to report suspected fraud to Action Fraud at actionfraud.police.uk.
How Did This Happen When AI-Powered Detection Exists?
The question most security professionals ask after a credential-exposure breach is not “why didn’t they detect the intrusion?” It is “why was the credential in the JavaScript in the first place?”
Conventional intrusion detection looks for network anomalies: unusual login patterns, lateral movement across servers, unexpected outbound data flows. A request made through a legitimate API using a legitimate key looks identical in logs to normal application behavior. At MAG’s scale — millions of customer interactions annually across three airports — an attacker making API calls to export a customer database would be generating precisely the kind of traffic that Iterable sees every day.
This is a structural problem, not a surveillance gap. GitGuardian’s 2026 secrets sprawl research recorded approximately 28.65 million new hardcoded secrets exposed in public GitHub repositories in 2025 alone — a 34% year-over-year increase. The ClickUp incident earlier in 2026 demonstrated that a hardcoded API key in publicly visible JavaScript can sit undetected for 15 months. The pattern across FulcrumSec’s documented victims — Novo Nordisk’s embedded Azure credentials, youX’s unrotated tokens from 2021, LexisNexis’s unpatched vulnerability — is consistent: cloud-native environments accumulate credential debt and identity sprawl faster than security programs typically track, and the gaps persist until someone exploits them.
Crystal Morin, senior cybersecurity strategist at Sysdig, who published a detailed analysis of FulcrumSec’s tactics after the Novo Nordisk breach, wrote that the group’s documented playbook “isn’t that big” — and that its predictability is precisely what makes it defensible. Secrets scanning of JavaScript bundles, CI/CD pipelines, and code repositories before deployment; API keys scoped to the minimum privilege needed; behavioral detection on cloud identity rather than network anomalies — none of these are novel. They are the specific controls FulcrumSec’s victims have lacked.
How Did MAG Respond?
MAG’s response to questions about FulcrumSec’s specific claims has been limited. When BleepingComputer presented the group’s assertions about the 86-gigabyte dataset, the exposed credentials, and the upcoming-travel records, a company spokesperson declined to engage with any of them, referring instead to an updated statement.
“MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support,” the spokesperson said. MAG has not publicly confirmed or denied that Iterable was the third-party platform involved.
MAG said it restricted access to affected systems, engaged specialist cybersecurity advisers, and notified law enforcement and relevant authorities. The online Manage My Booking service was temporarily suspended as a precaution, directing customers to a phone line.
What Regulators Are Watching
MAG disclosed the breach within the 72-hour window required under UK GDPR: the company says it detected unauthorized access on August 25, 2026, and went public on August 27 — a 48-hour disclosure window that appears to satisfy Article 33’s notification requirement on timing, if not on content.
The ICO confirmed receipt of MAG’s breach report and said it is assessing the details. Whether a formal investigation follows will depend partly on what the ICO’s review of MAG’s underlying security practices reveals — specifically whether the credential management practices that left an Iterable API key in public JavaScript represent a systemic failure of the security obligations under UK GDPR Article 32.
Under UK GDPR, the maximum fine reaches £17.5 million (approximately $23.7 million USD at August 31, 2026 exchange rates) or 4% of global annual turnover — whichever is higher. At MAG’s reported annual revenue of approximately £1.5 billion (roughly $2.03 billion USD), the 4% figure would represent a theoretical ceiling of roughly £60 million (approximately $81 million USD). In practice, ICO fines in comparable UK data breaches involving contact data rather than financial or medical records have historically landed well below that ceiling. The ICO’s largest 2025 fine was £14 million (approximately $19 million USD), levied against Capita for security failures in a breach affecting approximately 6.6 million people.
At least one UK law firm organizing group action has signaled it is moving against MAG for the incident, following a pattern that has become routine in the UK following high-profile breaches.
What Affected Travelers Should Do Now
If you have booked car parking, used an airport lounge, purchased Fast Track security access, or registered for in-airport Wi-Fi at Manchester Airport, London Stansted, or East Midlands Airport at any point, your data may be among the 8.7 million records in the breach. If you have any of those upcoming travel bookings through the end of 2026, your itinerary details are specifically among the records FulcrumSec claims to have.
Practically: be suspicious of any unsolicited communication referencing your airport booking history, your parking confirmation, your lounge access, your Fast Track reference, or your travel schedule — particularly if the message cites specific dates, times, or booking details that only someone with access to your MAG account would know. That specificity does not make the message legitimate; it makes it a likely phishing attempt built on this dataset. Report suspected fraud to Action Fraud online or by calling 0300 123 2040. Avoid clicking links or opening attachments from any communication referencing this breach. MAG has stated it will never contact customers to request payment card details, banking information, or passwords.
Currency conversions in this article are based on the GBP-to-USD exchange rate as of August 31, 2026, and are approximate.
Frequently Asked Questions
How did hackers get into Manchester Airports Group’s systems without stealing passwords or hacking servers?
FulcrumSec claims it found Iterable API credentials embedded directly in the JavaScript code that MAG’s websites sent to visitors’ browsers. Any web page’s JavaScript is fully readable by anyone who opens browser developer tools — no login, no exploit, no password required. A credential embedded in that code is a credential exposed to the public internet. Once FulcrumSec had the Iterable API key, it could query Iterable’s customer database through normal API calls that look identical in server logs to legitimate marketing platform activity. No server was “broken into” in the traditional sense; the credential authorized access to everything the marketing platform held.
Was my data in this breach — and does FulcrumSec plan to publish it?
If you booked car parking, used a lounge, purchased Fast Track, or registered for Wi-Fi at Manchester, Stansted, or East Midlands airports, your data was likely among the 8.7 million records MAG confirmed were accessed. MAG says it has contacted all affected customers directly. FulcrumSec has stated it plans to publish the full dataset, though it told BleepingComputer it may withhold the approximately 200,000 upcoming-travel records because of their potential for “real-world harm” — a caveat the group also exercised during its Novo Nordisk breach in June 2026. Whether that pledge holds is unknown. Treat the data as potentially public and adopt the protective steps above accordingly.
What makes a UK postcode combined with travel details more dangerous than a typical email address exposure?
A UK postcode is not the equivalent of a US ZIP code. The UK Office for National Statistics notes that a typical small-user postcode covers approximately 15 addresses; some postcodes are assigned to a single property. Combined with a vehicle registration plate, a parking date, a departure terminal, and a booking reference, a UK postcode from this breach is effectively a home address and a travel schedule. That combination tells a criminal when a property is likely to be unoccupied and gives them enough specific booking knowledge to craft phishing messages that are convincingly personalized — identifying your actual upcoming trip rather than guessing at it.
What should I look for in suspicious messages, and who do I report them to?
Be specifically suspicious of any unsolicited message — email, text, or phone call — that references your actual booking history, upcoming travel dates, terminal, parking confirmation, or Fast Track purchase. Specificity is not a sign of legitimacy; it is a sign that the sender has your data from this breach. Do not click links, open attachments, or provide any information. Report the communication to Action Fraud at actionfraud.police.uk or by calling 0300 123 2040. If a call references your bank, call your bank back on the number printed on your card — never use a number provided by an incoming caller.
Click Here For The Original Source.
