Extortion group FulcrumSec claims Manchester Airports breach, theft of 86 GB of data

Gang says it may withhold upcoming-travel records to avoid 'real-world harm'

edit
By LineZotpaper
Published
Read Time2 min
Extortion group FulcrumSec has claimed responsibility for the data breach at Manchester Airports Group (MAG), saying it stole approximately 86 GB of data from the UK's largest airport operator. The group shared samples with BleepingComputer that appeared to contain detailed customer, booking and travel information beyond what MAG disclosed on August 27.

Manchester Airports Group, which operates Manchester, London Stansted and East Midlands airports, disclosed on August 27 that an unauthorized third party had stolen customer data. The company said the affected information came from car park, lounge and Fast Track bookings, as well as in-airport Wi-Fi registrations.

FulcrumSec has now claimed responsibility, telling BleepingComputer it obtained access using airport-specific Iterable API credentials exposed in client-side JavaScript. The group said it stole about 86 GB of data, including a roughly 21.5 GB Manchester customer export containing consolidated profiles that combined customer identifiers with historical booking activity and marketing classifications.

BleepingComputer said it validated one record by comparing it with a traveller's known Manchester Airport purchase history. The record accurately listed previous Fast Track purchases, booking and scheduled-arrival times, the terminal used, amounts paid, purchase references, total spending and the apparent purpose of the trips.

FulcrumSec also claims the stolen material includes nearly 200,000 records related to upcoming travel during the remainder of 2026, containing dates, times and booking information linked to personally identifiable information. The group says it intends to publish the data and a technical account of the intrusion, but is considering withholding or redacting those upcoming-travel records because of the potential for "real-world harm."

BleepingComputer said it could not independently verify the alleged source or extent of the threat actor's access, the overall size of the stolen dataset, or the claim concerning nearly 200,000 upcoming-travel records. After completing its verification, the outlet said it securely deleted all supplied material and would not publish or share any part of it.

FulcrumSec is a financially motivated data-extortion group active since 2025 that focuses on stealing sensitive corporate data and threatening to publish it rather than encrypting victims' systems. The group has previously claimed attacks on organizations including LexisNexis and Novo Nordisk.

§

Analysis

Why This Matters

  • MAG operates three major UK airports, and the breach affects passengers who used parking, lounge, Fast Track or Wi-Fi services.
  • If FulcrumSec publishes the data, detailed personal travel histories and upcoming itineraries could be exposed, raising privacy and physical-security concerns.
  • The alleged attack vector — credentials exposed in client-side JavaScript — highlights a common but often overlooked web security risk.

Background

Manchester Airports Group disclosed on August 27 that an unauthorized third party had stolen customer data related to its three airports. FulcrumSec is a financially motivated extortion group active since 2025 that specializes in stealing sensitive corporate data and threatening to publish it, rather than deploying ransomware. The group has previously claimed attacks on companies including LexisNexis and Novo Nordisk. Independent verification of extortion-group claims is often difficult, and BleepingComputer was able to confirm only a single sample record against known purchase history.

Key Perspectives

Manchester Airports Group: The airport operator has confirmed that customer data from car park, lounge, Fast Track and Wi-Fi registrations was stolen, but has not detailed the full scope of the exposure.

FulcrumSec: The extortion group claims it stole 86 GB of data using Iterable API credentials found in client-side JavaScript. It says it intends to publish the data and a technical account, but is weighing whether to redact upcoming-travel records to avoid "real-world harm."

Critics/Skeptics: BleepingComputer could not independently verify the size of the dataset, the extent of the access, or the claim of nearly 200,000 upcoming-travel records. The authenticity of the samples does not confirm the group's broader assertions about the breach.

What to Watch

  • Whether FulcrumSec follows through on its promise to publish the stolen data and any technical write-up.
  • Whether MAG issues further disclosures or updates as its investigation continues.
  • Additional security researchers or affected travellers coming forward to confirm or challenge the group's claims.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.