The Manchester Airport Group (MAG) data breach was claimed by the extortion group FulcrumSec, which told BleepingComputer that it stole approximately 86GB of data.
Samples reviewed by BleepingComputer contained information consistent with MAG’s public disclosures. However, they suggest the breach may have exposed substantially more detailed customer, reservation and travel information than the airport operator initially reported.
FulcrumSec claims it stole 86GB of Manchester Airport data
Manchester Airports Group (MAG), the UK’s largest airport operator, disclosed on August 27 that an unauthorized third party had accessed and stolen customer data associated with Manchester Airport, London Stansted Airport and East Midlands Airport.
MAG said the compromised information was linked to parking, airport lounge and Fast Track reservations, as well as airport Wi-Fi registrations.
FulcrumSec claimed responsibility for the cyberattack in an email to BleepingComputer and provided samples of the allegedly stolen data as evidence.
BleepingComputer verified one of the records by comparing it with the traveler’s known purchase history at Manchester Airport.
The record accurately reflected previous Fast Track purchases, reservations and estimated arrival times. It also included details about the devices used, amounts paid, purchase references, total spending and the apparent purpose of the trip.
The data allegedly includes approximately 21.5GB of Manchester customer exports containing integrated profiles that link customer IDs with previous booking activity and marketing classifications.
FulcrumSec claims it gained access through airport-specific Iterable API credentials exposed in client-side JavaScript. The group also alleges that the stolen data contains approximately 200,000 records related to trips scheduled for the remainder of 2026.
These records allegedly include travel dates, times and reservation details associated with personally identifiable information.
FulcrumSec said it plans to publish the stolen data along with a technical explanation of the breach. However, the group told BleepingComputer that it may withhold or redact some records because of the potential for “real-world harm.”
Although the reviewed samples appeared to be genuine, BleepingComputer could not independently verify the original source of the data, the full extent of the attackers’ access, the total size of the stolen dataset or the claim involving nearly 200,000 future travel records.
After reviewing the samples, BleepingComputer will securely delete all submitted materials. No copies will be retained, published or shared.
FulcrumSec is a financially motivated data extortion group that has been active since 2025. Rather than encrypting victims’ systems, the group focuses on stealing sensitive corporate data and threatening to publish it.
The group has previously targeted or advocated attacks against organizations including LexisNexis, Novo Nordisk, a global school group and Avnet.
Manchester Airport operator does not address FulcrumSec claims
BleepingComputer contacted MAG again before publication and asked the company to respond to FulcrumSec’s claims about the 86GB dataset, exposed credentials and alleged future travel records.
The company spokesperson did not address the specific allegations, instead referring to an updated statement confirming that customers with future reservations had been contacted.
A MAG spokesperson told BleepingComputer: “MAG is confident that we have taken effective steps to protect our customers and have contacted all those affected, including contacting all future booking holders and directing them to additional support.”
Manchester Airport data breach may be broader than first reported
In addition to the email addresses, phone numbers, vehicle registrations and postal codes disclosed by MAG, the reviewed samples contained purchase and reservation references, airport and product selections, prices, discounts, reservation status, parking dates and times, historical spending amounts, IP addresses, approximate location, device information and customer engagement data.
BleepingComputer did not observe payment card or bank account information in the samples it reviewed.
Unlike US ZIP codes, which generally cover large delivery areas, full UK postcodes can identify relatively small groups of nearby properties. According to the UK Office for National Statistics, a typical small-user postcode covers approximately 15 addresses, although some postcodes are assigned to a single address.
When combined with contact, vehicle and travel information, these details could help attackers create convincing phishing emails, text messages or phone scams impersonating MAG, an airport service or a reservation provider. Scammers could potentially identify a victim’s airport, vehicle, parking dates, reservation status and purchased services.
MAG said it has contacted affected customers and advised them to remain alert for suspicious emails, text messages and phone calls.
The airport operator stressed that it will never unexpectedly contact customers to request payment card details, banking information or passwords.
The data breach did not cause operational disruption, and MAG said passenger safety and aviation security were not compromised.
Previously, a MAG public relations officer told the Manchester Evening News that approximately 8.7 million customers were affected. However, the company said that the “vast majority” of those customers had only their email addresses exposed.
The incident is the largest known customer data breach to affect a UK airport operator.
With files from Bill Toulas
The overall prevention score can hide what happens after initial access. If an attacker uses valid credentials, your defenses can drop sharply.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




