FulcrumSec claims Manchester Airports hack, theft of 86 GB of data

Summary: FulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information beyond what MAG initially disclosed. [...]

FulcrumSec Claims Manchester Airports Breach Exposed Detailed Travel Data

A cyberattack against Manchester Airports Group is beginning to look more serious than the company’s initial disclosure suggested. The financially motivated extortion group FulcrumSec has claimed responsibility for the intrusion, telling BleepingComputer that it stole approximately 86 GB of data containing detailed information about airport customers, bookings and travel activity.

Manchester Airports Group (MAG), the UK’s largest airport operator, disclosed the breach on August 27. The incident affected information associated with Manchester Airport, London Stansted and East Midlands Airport, including data collected through car park, lounge and Fast Track bookings as well as airport Wi-Fi registrations. Airport operations were not disrupted and MAG says passenger safety and aviation security were not affected.

The stolen information appears more detailed than first disclosed

MAG initially identified exposed information including email addresses, phone numbers, vehicle registration numbers and postcodes. FulcrumSec subsequently provided BleepingComputer with samples that appeared to contain considerably richer customer profiles.

BleepingComputer independently validated one record against a traveler’s known Manchester Airport purchase history. The information accurately reflected previous Fast Track purchases, booking and scheduled arrival times, terminals, amounts paid, purchase references, total spending and apparent travel purposes.

The samples also included booking references, airport and product selections, discounts, parking dates and times, IP addresses, approximate locations, device information and customer-engagement data. BleepingComputer did not find payment-card or bank-account information in the material it examined.

That distinction matters. A dataset does not need passwords or credit-card numbers to create substantial security risks. Detailed knowledge about where someone parks, which airport they use and when they are expected to travel can make subsequent fraud and impersonation attempts considerably more convincing.

FulcrumSec claims nearly 200,000 future trips are exposed

One of the group’s most concerning allegations involves upcoming travel.

FulcrumSec claims the stolen information contains nearly 200,000 records associated with travel scheduled during the remainder of 2026, connecting dates, times and booking information with personally identifiable information. The group told BleepingComputer it was considering withholding or redacting those records if it publishes the stolen dataset because of their potential to cause real-world harm.

BleepingComputer could not independently verify the 200,000-record claim, the complete 86 GB figure or the full extent of the attackers’ access. Those numbers should therefore be treated as assertions from the extortion group rather than established facts.

Nevertheless, the samples that could be checked were sufficiently credible to support MAG’s broader acknowledgement that customer information had been stolen.

Exposed API credentials may have provided the entry point

FulcrumSec also offered a technical explanation for how it claims to have obtained access. According to the group,airport-specific Iterable API credentials were exposed in client-side JavaScript, providing a route into customer information.

MAG has not confirmed that explanation. When BleepingComputer asked the airport operator about the alleged exposed credentials, 86 GB dataset and future-travel information, the company declined to address those claims individually.

MAG instead said it had taken measures to protect customers and had contacted affected individuals, including customers with upcoming bookings who may require additional support.

If FulcrumSec’s account of the initial access is eventually confirmed, however, the incident would illustrate a familiar application-security problem. Secrets embedded in client-side applications should generally be treated as exposed because JavaScript delivered to a browser can be inspected by anyone using the application. Credentials that provide meaningful backend access can therefore turn what appears to be a minor development mistake into a large-scale data breach.

Travel information creates unusually convincing phishing opportunities

MAG previously said approximately 8.7 million customers were affected, although email addresses were the only exposed information for the vast majority of them. That would make the incident the largest known customer data breach involving a British airport operator.

The smaller subset containing detailed booking information may present the greater security concern.

An attacker who knows that a victim has booked parking at Manchester Airport on a particular date could send a message claiming that the reservation requires confirmation. Knowledge of the terminal, vehicle registration, booking reference or Fast Track purchase would make the communication appear significantly more authentic than generic phishing.

British postcodes can add another layer of specificity. Unlike broader geographic ZIP codes used in some countries, a full UK postcode frequently corresponds to a small number of properties. Combined with phone numbers, vehicles and travel dates, the resulting profile can become surprisingly precise.

MAG is consequently warning affected customers to be cautious about unexpected emails, SMS messages and telephone calls. The company stresses that it will not unexpectedly ask customers to provide passwords, banking information or payment-card details.

FulcrumSec relies on data theft rather than ransomware encryption

FulcrumSec has been active since 2025 and operates primarily as a data-extortion group. Instead of necessarily encrypting corporate systems and demanding payment for recovery, the group focuses on stealing sensitive information and threatening to publish it unless victims meet its demands.

That model helps explain why the Manchester Airports incident could remain invisible to passengers while still becoming a major breach. Airport systems continued functioning, parking services remained operational and flights were unaffected. The attacker’s objective was apparently the information behind those services rather than the services themselves.

This distinction is increasingly important in modern incident response. Reliable backups can help an organization recover from ransomware encryption, but they cannot undo data exfiltration. Once information has left the network, organizations must assume that copies may continue to exist regardless of whether the original vulnerability is fixed.

The breach shows the value of contextual data

The Manchester Airports incident is ultimately significant because of the context surrounding the stolen information.

An email address by itself has limited value. An email address connected to a phone number, vehicle registration, postcode, airport, terminal, booking reference, parking dates, previous purchases and an upcoming journey is something very different.

That information can transform generic social engineering into personalized impersonation. It can allow an attacker to demonstrate knowledge that a victim would reasonably expect only the airport or booking provider to possess.

MAG says it has taken steps to contain the incident and contact affected customers, while FulcrumSec says the airport operator appears unwilling to meet its demands. What remains uncertain is how much of the group’s claimed 86 GB dataset will ultimately be released.

The breach therefore illustrates an increasingly important lesson about data security:the sensitivity of a dataset is determined not only by individual fields, but by what attackers can learn when those fields are combined into a detailed picture of a person’s real-world activity.

⁠Original report at BleepingComputer

Key facts

  • FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group
  • The stolen data reportedly includes detailed customer, booking, and travel information
  • BleepingComputer has validated at least one traveler's record from the alleged data theft
  • The breach potentially exposes sensitive information beyond what Manchester Airports Group initially disclosed

Why it matters

This alleged data breach highlights significant cybersecurity vulnerabilities within critical aviation infrastructure. If confirmed, the theft of such a large dataset, potentially including detailed customer and booking information, could have severe implications for passenger privacy, operational integrity, and regulatory compliance for airport authorities and airlines operating within the affected systems.