FulcrumSec Claims Manchester Airport Data Breach, 86GB of Data Stolen

www.news4hackers.com-fulcrumsec-claims-manchester-airport-data-breach-86gb-of-data-stolen-fulcrumsec-claims-manchester-airport-data-breach-86gb-of-data-stolen

A cybercriminal group named FulcrumSec has claimed responsibility for a data breach at Manchester Airports Group, exposing 86GB of customer data.

The Breach and Data Exposed

A cybercriminal group known as FulcrumSec has asserted responsibility for a data breach at Manchester Airports Group, alleging the theft of 86 gigabytes of information. The breach, which impacted operations at Manchester, London Stansted, and East Midlands airports, involved customer data from car park, lounge, and Fast Track booking systems, as well as in-airport Wi-Fi registrations.

Details of the Stolen Data

The group shared sample datasets with BleepingComputer, which included records matching verified traveler purchase histories, such as Fast Track reservations, scheduled arrival times, terminal details, payment references, and trip purposes. The stolen material reportedly contains a 21.5 GB export of customer profiles consolidating identifiers with historical booking activity and marketing classifications.

Sample Datasets and Verification

FulcrumSec claims access was achieved through airport-specific Iterable API credentials exposed in client-side JavaScript. The group alleges the dataset includes nearly 200,000 records tied to travel plans for the remainder of 2026, featuring personally identifiable information linked to travel dates, booking details, and related metadata.

Verification and Data Scope

BleepingComputer confirmed the authenticity of one sample record by cross-referencing it with a traveler’s known purchase history but could not independently verify the full dataset’s scope or the accuracy of the 200,000-record claim. All provided materials were securely deleted without retention.

Method of Access and Group’s Claims

FulcrumSec, a financially motivated extortion group active since 2025, has previously targeted organizations such as LexisNexis, Novo Nordisk, and Avnet. Manchester Airports Group stated it has notified affected customers and emphasized that no payment-card or banking information was compromised.

Impact on Operations and Security

The breach did not disrupt airport operations or aviation security. However, sampled records revealed additional data points beyond what was initially disclosed, including booking references, product selections, IP addresses, device details, and customer-engagement metrics.

Impact on Customers and Security Risks

UK postcodes, which can narrow down locations to as few as 15 addresses, combined with travel and vehicle data, could enable sophisticated phishing campaigns impersonating the airport or booking providers. MAG confirmed it has advised customers to remain vigilant against suspicious communications and reiterated that it would not request sensitive information via unsolicited contact.

Previous Breach Details

The company previously reported that approximately 8.7 million customers were impacted, with the majority affected by exposure of addresses. This incident represents the largest known data breach involving a British airport operator.

Cybersecurity Expert Insights

The breach highlights vulnerabilities in API credential management and the risks of exposing sensitive customer data through client-side scripting. Cybersecurity experts caution that such breaches can enable targeted fraud schemes, emphasizing the importance of multi-layered defense strategies and continuous monitoring for unauthorized access.

According to BleepingComputer, “BleepingComputer confirmed the authenticity of one sample record by cross-referencing it with a traveler’s known purchase history but could not independently verify the full dataset’s scope or the accuracy of the 200,000-record claim.”



About Author

en_USEnglish