What Happened
FulcrumSec, a financially motivated data-extortion group active since 2025, claims to have stolen approximately 86GB of data from Manchester Airports Group (MAG), the operator of Manchester, London Stansted, and East Midlands airports. The group says it obtained access using airport-specific Iterable API credentials exposed in client-side JavaScript. BleepingComputer validated a sample record against a known traveller's purchase history, confirming its accuracy. MAG has confirmed a breach but declined to address the specific scope of the group's claims, and says there was no operational disruption or aviation security compromise.
Incident Details
| Attribute | Value |
|---|---|
| Threat Actor | FulcrumSec (financially motivated extortion group, active since 2025) |
| Data Volume | ~86GB |
| Vector | Airport-specific Iterable API credentials allegedly exposed in client-side JavaScript |
| Customers Affected | ~8.7 million across Manchester, London Stansted & East Midlands airports |
| Prior Claimed Targets | LexisNexis, Novo Nordisk, Global Schools Group, Avnet |
| MAG's Response | Confirms breach, declines to verify scope; contacted all affected customers |
What Was Exposed
The data reviewed by BleepingComputer included customer identifiers, historical booking activity, marketing classifications, purchase and booking references, prices and discounts, parking dates and times, IP addresses, device information, and customer-engagement data. Payment card and bank account information were not observed in the samples reviewed. For the "vast majority" of the roughly 8.7 million affected customers, email addresses were the primary data exposed. Notably, nearly 200,000 records allegedly contain dates, times, and booking details tied to upcoming travel later in 2026, raising concerns about targeted phishing against travellers with confirmed itineraries.
How the Breach Allegedly Happened
FulcrumSec claims it obtained access through Iterable API credentials specific to the airports, which were exposed in client-side JavaScript — a class of exposure that typically stems from API keys or tokens embedded directly in front-end code rather than kept server-side. Iterable is a customer-engagement and marketing-automation platform, consistent with the marketing-classification and customer-engagement data found in the leaked samples.
MAG's Response
Manchester Airports Group has not addressed the specific volume or scope of data FulcrumSec claims to have stolen. In a statement, MAG said: "we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support." The operator confirmed the incident caused no operational disruption and did not compromise aviation security.
Impact Assessment
| Impact Area | Description |
|---|---|
| Customer Exposure | ~8.7 million customers affected, primarily via email address exposure |
| Targeted Phishing Risk | ~200,000 records tied to specific upcoming 2026 travel dates create a targeted phishing/social-engineering risk |
| Financial Data | No payment card or bank data observed in reviewed samples |
| Operational Impact | MAG states no disruption to airport operations or aviation security |
| Reputational Risk | FulcrumSec has a track record of prior claimed breaches against LexisNexis, Novo Nordisk, and others |
Recommendations
For Affected Customers
- Treat unsolicited emails referencing airport bookings, parking, or Fast Track purchases with heightened suspicion, especially those tied to travel later in 2026.
- Do not click links or provide payment details in response to unexpected "booking update" or "travel support" emails — verify directly through MAG's official channels.
- Monitor for phishing attempts that reference accurate personal booking details, since attackers with this data can craft highly convincing lures.
For Organizations Using Third-Party Marketing/Engagement Platforms
- Audit client-side JavaScript for hardcoded or exposed API credentials tied to marketing and customer-engagement platforms such as Iterable.
- Scope third-party API keys to the minimum required permissions, and rotate any credentials that may have been exposed in front-end code.
- Treat customer-engagement platforms as sensitive data stores — they often aggregate PII well beyond what their "marketing" label suggests.
Key Takeaways
- FulcrumSec claims to have stolen 86GB of data affecting roughly 8.7 million Manchester Airports Group customers.
- The group alleges access via exposed Iterable API credentials in client-side JavaScript — not a core aviation-systems breach.
- No payment card data was found in reviewed samples; email addresses were the primary exposure for most customers.
- Nearly 200,000 records reportedly include upcoming 2026 travel details, elevating targeted-phishing risk for those customers.
- MAG confirmed the breach but has not verified FulcrumSec's specific claims, and reports no operational or aviation-security impact.