Extortion Group Alleges Cyberattack on Manchester Airports Group Data Breach
The FulcrumSec extortion group has asserted responsibility for a data breach impacting the Manchester Airports Group (MAG).
Details of the Breach
The UK-based airport operator, which manages Manchester, London Stansted, and East Midlands airports, disclosed the incident on August 27. The breach involved unauthorized access to information linked to car park, lounge, and Fast Track reservations, as well as Wi-Fi registrations at all three facilities.
MAG’s Response and Mitigation
MAG stated it immediately mitigated the risk and collaborated with cybersecurity experts to safeguard systems and customers. The organization confirmed it notified relevant authorities and emphasized that no financial data was compromised.
Impact on Operations and Data
Passenger safety and aviation security remained unaffected, with no operational disruptions reported. MAG noted that customer parking services continue to function normally. While the exact number of affected individuals was not disclosed, preliminary estimates indicated approximately 8.7 million customers might have had personal details exposed.
Compromised Data and Third-Party Involvement
The compromised data included addresses, phone numbers, vehicle registration numbers, and postal codes. MAG revealed the breach originated from a database managed by a third-party vendor and mentioned receiving a ransom demand, though it did not provide specifics about the attackers or their requirements.
FulcrumSec’s Background
FulcrumSec, a financially motivated threat actor that emerged in 2025, has previously claimed responsibility for breaches targeting organizations such as Novo Nordisk and LexisNexis. The group reportedly stole 86 gigabytes of data from MAG, including detailed travel and booking records, and plans to release the stolen information.
Conclusion
No further details about the breach’s technical mechanisms or the threat actor’s methods were disclosed.
