Extortion Group Claims 86GB Theft From Manchester Airports Group
The claim raises the prospect that exposed third‑party API credentials allowed access to detailed booking and travel records.
Overview
- Manchester Airports Group disclosed the customer‑data breach on Thursday and said about 8.7 million customers were affected with the vast majority limited to email addresses.
- Extortion group FulcrumSec told reporters it stole roughly 86 gigabytes of MAG data and supplied samples that a journalist validated against a traveller’s known purchase history.
- FulcrumSec says the attackers used Iterable API credentials left in client‑side JavaScript, which would let anyone inspecting a site’s browser code reuse those credentials to query back‑end records.
- MAG says no payment‑card or banking data were exposed, that airport operations and passenger safety were not affected, and that it has contacted customers with upcoming bookings while declining to confirm the attacker’s technical or volume claims.
- Security specialists and investigators remain engaged because publication of the stolen files could enable targeted phishing using full UK postcodes, vehicle registrations and booking details and because reliance on third‑party booking or marketing platforms increases supply‑chain risk.