Extortion Group FulcrumSec Claims Responsibility for Manchester Airports Group Cyberattack and Theft of 86 GB of Data

Extortion group FulcrumSec has claimed responsibility for the recent cyberattack against Manchester Airports Group, stating that approximately 86 GB of sensitive traveler data was exfiltrated during the breach.

Manchester Airports Group (MAG), the largest airport operator in the United Kingdom, initially disclosed on August 27, 2026, that unauthorized third-party actors had accessed customer records linked to Manchester, London Stansted, and East Midlands airports. The initial disclosure indicated that information stemmed primarily from car park, lounge, and Fast Track bookings, alongside in-airport Wi-Fi registrations.

However, subsequent claims and data samples provided by FulcrumSec indicate that the breach exposed significantly more granular customer, booking, and travel information than previously acknowledged. Independent reviews of the leaked material confirmed the presence of detailed historical purchase records, terminal selections, scheduled arrival times, pricing, and specific transaction references.

According to the extortion group, access to the systems was secured by exploiting airport-specific Iterable API credentials that had been improperly exposed within client-side JavaScript. FulcrumSec asserts that the stolen cache contains roughly 200,000 records detailing upcoming travel schedules for the remainder of 2026, combining personal identifiers with specific itinerary dates and timestamps.

Operating as a financially motivated data-extortion entity since 2025, FulcrumSec typically focuses on stealing sensitive information and threatening public exposure rather than deploying traditional file-encrypting ransomware. The group’s past targets include major enterprise and technology organizations such as LexisNexis, Novo Nordisk, Global Schools Group, and Avnet.

When asked to address FulcrumSec’s specific assertions regarding the 86 GB dataset and exposed API credentials, representatives for Manchester Airports Group declined to comment directly, pointing instead to prior statements confirming that affected customers with upcoming itineraries have been notified. “MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support,” a MAG spokesperson stated.

Although the reviewed data samples did not expose direct payment-card numbers or banking credentials, security analysts warn that the combination of full UK postcodes, vehicle registrations, and precise flight timings creates significant risks for targeted phishing and social engineering campaigns. MAG has urged all travelers to remain vigilant regarding unexpected communications while confirming that core operational safety and aviation infrastructure remain unaffected.

Leave a Reply

Your email address will not be published. Required fields are marked *