Manchester Airports Group, which operates Manchester, London Stansted and East Midlands airports, disclosed on August 27 that an unauthorized third party had stolen customer data. The company said the affected information came from car park, lounge and Fast Track bookings, as well as in-airport Wi-Fi registrations.
FulcrumSec has now claimed responsibility, telling BleepingComputer it obtained access using airport-specific Iterable API credentials exposed in client-side JavaScript. The group said it stole about 86 GB of data, including a roughly 21.5 GB Manchester customer export containing consolidated profiles that combined customer identifiers with historical booking activity and marketing classifications.
BleepingComputer said it validated one record by comparing it with a traveller's known Manchester Airport purchase history. The record accurately listed previous Fast Track purchases, booking and scheduled-arrival times, the terminal used, amounts paid, purchase references, total spending and the apparent purpose of the trips.
FulcrumSec also claims the stolen material includes nearly 200,000 records related to upcoming travel during the remainder of 2026, containing dates, times and booking information linked to personally identifiable information. The group says it intends to publish the data and a technical account of the intrusion, but is considering withholding or redacting those upcoming-travel records because of the potential for "real-world harm."
BleepingComputer said it could not independently verify the alleged source or extent of the threat actor's access, the overall size of the stolen dataset, or the claim concerning nearly 200,000 upcoming-travel records. After completing its verification, the outlet said it securely deleted all supplied material and would not publish or share any part of it.
FulcrumSec is a financially motivated data-extortion group active since 2025 that focuses on stealing sensitive corporate data and threatening to publish it rather than encrypting victims' systems. The group has previously claimed attacks on organizations including LexisNexis and Novo Nordisk.