All incidents

FulcrumSec claims data breach of Manchester Airports Group affecting 8.7 million

breachopenAug 30, 2026 — Aug 31, 2026
FulcrumSec claims data breach of Manchester Airports Group affecting 8.7 million

FULCRUMSEC has claimed responsibility for a data breach at Manchester Airports Group that allegedly exposed the personal details of 8.7 million customers, a disclosure made public on 27 August. The group says it obtained email addresses, phone numbers, vehicle registrations and postcodes, though it insists no payment card information was taken. Manchester Airports Group confirmed the incident involved a third‑party database and said operational safety was not compromised.

According to analysis shared by the attackers, the breach originated from API credentials that were inadvertently left in client‑side JavaScript, allowing anyone inspecting the web pages to harvest the keys. The stolen dataset is reported to be around 86 gigabytes in size and includes roughly 200 000 records that link travel itineraries to personally identifiable information. No CVE identifier has been assigned to the flaw.

FulcrumSec is known for extortion‑focused intrusions and has threatened to publish the harvested data unless a ransom is paid. Security researchers have not yet observed the material appearing on underground forums, but the group’s track record suggests a follow‑up leak is possible. Manchester Airports Group said it has contained the exposure and is cooperating with law‑enforcement agencies.

The airport operator advised affected individuals to remain vigilant for phishing attempts that may use the leaked contact details and to monitor any unusual activity on their online accounts. It also noted that because no financial data was accessed, the direct risk of fraud is limited, but warned that aggregated personal information could still be leveraged for social engineering.

Defenders should audit front‑end code for hard‑coded secrets and ensure that any API keys or tokens are stored securely behind a gateway or vault. Implementing runtime inspection tools that flag unexpected data exfiltration from JavaScript can help catch similar oversights early. Organisations should also review third‑party data sharing agreements and enforce strict access controls on repositories that hold customer information. Finally, maintaining an up‑to‑date incident response plan that includes clear communication steps will improve resilience when faced with extortion‑style threats.

Intelligence briefing updated Aug 31, 2026

FulcrumSec
Timeline Coverage

Swipe to explore timeline