Particle.news
Download on the App Store

Hackers Publish Data on 8.8 Million Customers of Manchester Airports Group

Security experts warn the exposure of personal contacts and booking records raises the risk of targeted scams, impersonation, and possible home-targeting.

Overview

  • The extortion group FulcrumSec posted roughly 549–550GB of stolen data on Wednesday, which HaveIBeenPwned parsed as about 8.7–8.8 million compromised records of customers who used Manchester, London Stansted and East Midlands airport services.
  • Manchester Airports Group says the data came from a third-party database, it refused the ransom demand, has contacted affected customers, and maintains that no bank or payment card details or core flight operations were compromised.
  • The leaked files reportedly include emails, phone numbers, postcodes, vehicle registrations, browser and IP details plus millions of parking, lounge and Fast Track booking records that could be used to craft highly convincing phishing and smishing attacks.
  • FulcrumSec claims it gained access after finding Iterable admin keys embedded in frontend JavaScript on each airport site, a vector experts say highlights common supply‑chain and credential‑exposure mistakes by developers and vendors.
  • Security teams and UK cyber bodies are investigating and advising vigilance; affected people should expect targeted contact about bookings, avoid clicking links in unsolicited messages, use unique passwords and two‑factor authentication, and check HaveIBeenPwned for notifications.