FulcrumSec claims Manchester Airports hack, theft of 86 GB of data

airport

The Manchester Airports Group data breach has been claimed by extortion group FulcrumSec, which told BleepingComputer that it stole approximately 86 GB of data.

Samples reviewed by BleepingComputer contained information consistent with MAG’s disclosure while indicating that the breach exposed considerably more detailed customer, booking, and travel information than initially revealed.

Hackers claim theft of 86 GB of data

Manchester Airports Group (MAG), the United Kingdom’s largest airport operator, disclosed on August 27 that an unauthorized third party had stolen customer data related to Manchester, London Stansted, and East Midlands airports.

image

The company said the affected information came from car park, lounge, and Fast Track bookings and in-airport Wi-Fi registrations.

In emails to BleepingComputer, FulcrumSec claimed responsibility for the attack and shared samples of the allegedly stolen data as evidence.

BleepingComputer validated one record by comparing it with the traveller’s known Manchester Airport purchase history.

The record accurately listed previous Fast Track purchases, booking and scheduled-arrival times, the terminal used, amounts paid, purchase references, total spending and the apparent purpose of the trips.

The material included a roughly 21.5 GB Manchester customer export containing consolidated profiles that combined customer identifiers with historical booking activity and marketing classifications.

The group claims it obtained access using airport-specific Iterable API credentials exposed in client-side JavaScript and that the stolen material includes nearly 200,000 records related to upcoming travel during the remainder of 2026.

These records allegedly contain dates, times and booking information linked to personally identifiable information.

FulcrumSec says it intends to publish the stolen data and a technical account of the intrusion. However, it told BleepingComputer that it is considering withholding or redacting those records because of the potential for “real-world harm.”

While the samples appeared authentic, BleepingComputer could not independently verify the alleged source or extent of the threat actor’s access, the overall size of the stolen dataset, or the claim concerning nearly 200,000 upcoming-travel records.

After completing its verification, BleepingComputer securely deleted all supplied material without retaining copies and will not publish or share any part of it.

FulcrumSec is a financially motivated data-extortion group active since 2025 that focuses on stealing sensitive corporate data and threatening to publish it rather than encrypting victims’ systems.

The group has previously claimed attacks on organizations including LexisNexis, Novo Nordisk, Global Schools Group, and Avnet.

MAG declines to address hackers’ claims

BleepingComputer contacted MAG again before publication and asked the company to address FulcrumSec’s claims concerning the 86 GB dataset, exposed credentials and future-travel data.

A spokesperson declined to address the specific claims, referring instead to an updated statement confirming that affected customers with upcoming bookings had been contacted.

“MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support,” a MAG spokesperson told BleepingComputer.

The attackers reportedly demanded a monetary ransom, which MAG was understood to have refused to pay.

Scope appears broader than initially suggested

Beyond the email addresses, phone numbers, vehicle registrations and postcodes disclosed by MAG, sampled records contained purchase and booking references, airport and product selections, prices, discounts, booking status, parking dates and times, historical spending, IP addresses, approximate locations, device information and customer-engagement data.

BleepingComputer did not observe payment-card or bank-account information in the reviewed samples.

Unlike US ZIP codes, which generally cover broader delivery areas, a full UK postcode can identify a small group of neighboring properties. According to the UK Office for National Statistics, a typical small-user postcode covers approximately 15 addresses, while some postcodes are assigned to a single address.

Combined with contact, vehicle and travel information, these details could allow attackers to reference a victim’s airport, vehicle, parking dates, booking status or purchased services in convincing phishing emails, text messages or telephone scams impersonating MAG or a booking provider.

MAG said it has contacted affected customers and advised them to remain vigilant for suspicious emails, text messages, and telephone calls.

The airport operator stressed that it would never contact customers unexpectedly to request payment-card details, banking information, or passwords.

The incident has not caused operational disruption, and MAG says passenger safety and aviation security were not compromised.

A MAG spokesperson previously told the Manchester Evening News that around 8.7 million customers were affected, although only email addresses were exposed for the “vast majority.”

That makes it the largest known customer data breach affecting a British airport operator.

With files from Bill Toulas

article image

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report