Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2604+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. FulcrumSec Claims Manchester Airports Hack, Theft of 86GB of Data
FulcrumSec Claims Manchester Airports Hack, Theft of 86GB of Data
NEWS

FulcrumSec Claims Manchester Airports Hack, Theft of 86GB of Data

Extortion group FulcrumSec claims it stole 86GB of data from Manchester Airports Group, affecting roughly 8.7 million customers across three UK airports.

Dylan H.

News Desk

August 30, 2026
4 min read

What Happened

FulcrumSec, a financially motivated data-extortion group active since 2025, claims to have stolen approximately 86GB of data from Manchester Airports Group (MAG), the operator of Manchester, London Stansted, and East Midlands airports. The group says it obtained access using airport-specific Iterable API credentials exposed in client-side JavaScript. BleepingComputer validated a sample record against a known traveller's purchase history, confirming its accuracy. MAG has confirmed a breach but declined to address the specific scope of the group's claims, and says there was no operational disruption or aviation security compromise.


Incident Details

AttributeValue
Threat ActorFulcrumSec (financially motivated extortion group, active since 2025)
Data Volume~86GB
VectorAirport-specific Iterable API credentials allegedly exposed in client-side JavaScript
Customers Affected~8.7 million across Manchester, London Stansted & East Midlands airports
Prior Claimed TargetsLexisNexis, Novo Nordisk, Global Schools Group, Avnet
MAG's ResponseConfirms breach, declines to verify scope; contacted all affected customers

What Was Exposed

The data reviewed by BleepingComputer included customer identifiers, historical booking activity, marketing classifications, purchase and booking references, prices and discounts, parking dates and times, IP addresses, device information, and customer-engagement data. Payment card and bank account information were not observed in the samples reviewed. For the "vast majority" of the roughly 8.7 million affected customers, email addresses were the primary data exposed. Notably, nearly 200,000 records allegedly contain dates, times, and booking details tied to upcoming travel later in 2026, raising concerns about targeted phishing against travellers with confirmed itineraries.


How the Breach Allegedly Happened

FulcrumSec claims it obtained access through Iterable API credentials specific to the airports, which were exposed in client-side JavaScript — a class of exposure that typically stems from API keys or tokens embedded directly in front-end code rather than kept server-side. Iterable is a customer-engagement and marketing-automation platform, consistent with the marketing-classification and customer-engagement data found in the leaked samples.


MAG's Response

Manchester Airports Group has not addressed the specific volume or scope of data FulcrumSec claims to have stolen. In a statement, MAG said: "we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support." The operator confirmed the incident caused no operational disruption and did not compromise aviation security.


Impact Assessment

Impact AreaDescription
Customer Exposure~8.7 million customers affected, primarily via email address exposure
Targeted Phishing Risk~200,000 records tied to specific upcoming 2026 travel dates create a targeted phishing/social-engineering risk
Financial DataNo payment card or bank data observed in reviewed samples
Operational ImpactMAG states no disruption to airport operations or aviation security
Reputational RiskFulcrumSec has a track record of prior claimed breaches against LexisNexis, Novo Nordisk, and others

Recommendations

For Affected Customers

  • Treat unsolicited emails referencing airport bookings, parking, or Fast Track purchases with heightened suspicion, especially those tied to travel later in 2026.
  • Do not click links or provide payment details in response to unexpected "booking update" or "travel support" emails — verify directly through MAG's official channels.
  • Monitor for phishing attempts that reference accurate personal booking details, since attackers with this data can craft highly convincing lures.

For Organizations Using Third-Party Marketing/Engagement Platforms

  • Audit client-side JavaScript for hardcoded or exposed API credentials tied to marketing and customer-engagement platforms such as Iterable.
  • Scope third-party API keys to the minimum required permissions, and rotate any credentials that may have been exposed in front-end code.
  • Treat customer-engagement platforms as sensitive data stores — they often aggregate PII well beyond what their "marketing" label suggests.

Key Takeaways

  1. FulcrumSec claims to have stolen 86GB of data affecting roughly 8.7 million Manchester Airports Group customers.
  2. The group alleges access via exposed Iterable API credentials in client-side JavaScript — not a core aviation-systems breach.
  3. No payment card data was found in reviewed samples; email addresses were the primary exposure for most customers.
  4. Nearly 200,000 records reportedly include upcoming 2026 travel details, elevating targeted-phishing risk for those customers.
  5. MAG confirmed the breach but has not verified FulcrumSec's specific claims, and reports no operational or aviation-security impact.

Sources

  • BleepingComputer — FulcrumSec claims Manchester Airports hack, theft of 86GB of data
#Data Breach#Extortion#Aviation#FulcrumSec#United Kingdom

Related Articles

Manchester Airports Group Confirms Data Breach — Up to 8.9M Travelers Affected

Hackers breached Manchester Airports Group, exposing traveler emails, phone numbers, and vehicle data across three UK airports.

3 min read

Council of Europe Investigates ShinyHunters Data Breach Claims

The Council of Europe, Europe's oldest intergovernmental body, is probing data breach claims made by the ShinyHunters extortion group, which claimed...

5 min read

LexisNexis Confirms Cloud Breach Exposing 400K User

LexisNexis Legal & Professional confirms a data breach after threat actor FulcrumSec exploited an unpatched React2Shell vulnerability to exfiltrate 2.04...

4 min read
Back to all News