FulcrumSec Claims Breach of Manchester Airports Group via Exposed API Keys
The threat group alleges it stole data from 8.7 million customers after finding admin credentials in the airports' public website code.
The threat group FulcrumSec has claimed responsibility for a massive data breach affecting Manchester Airports Group (MAG), the operator of Manchester, London Stansted, and East Midlands airports. The incident has exposed the personal information of millions of travelers, highlighting a critical security failure in how the group managed its third-party software integrations.
According to the group, the breach was facilitated by the discovery of admin keys for 'Iterable,' a customer engagement platform. These credentials were allegedly left exposed in the frontend JavaScript of the root domains for all three airport websites. FulcrumSec claims to have exfiltrated approximately 86 GB of data, which includes records for roughly 8.7 million customers. The stolen information spans various services, including car park bookings, lounge access, Fast Track reservations, and in-airport Wi-Fi sign-ups. Additionally, the group claims the stolen material includes nearly 200,000 records related to upcoming travel.
The Security Oversight
MAG first acknowledged a "cyber incident" on August 27, confirming that unauthorized third parties had accessed customer data such as email addresses, phone numbers, and vehicle registrations. While the company focused on containing the risk and verifying the validity of existing bookings, the claims from FulcrumSec suggest a more systemic vulnerability. The group noted that no complex hacking techniques were required to gain entry, stating that any visitor to the site could have simply used a browser's 'inspect' tool to find the keys "plain as day."
MAG has confirmed that bank and payment details were not stored on the affected system, mitigating the immediate risk of direct financial theft from the breached database.
Industry Implications
The breach places millions of travelers at an elevated risk of highly targeted phishing and "smishing" (SMS phishing) attacks. Because the attackers possess legitimate travel-related details, they can craft convincing messages to deceive victims into revealing further sensitive information. Raghu Nandakumara, VP of industry strategy at Illumio, noted that the exposure of this specific data makes malicious communications appear far more authentic to the affected users.
Beyond digital fraud, the theft of vehicle registrations and upcoming travel schedules introduces a potential physical security concern. Criminals with access to travel dates and vehicle information could theoretically identify when homeowners are away on holiday, increasing the risk of targeted residential burglaries.
What's Next
As the industry analyzes the fallout, the focus remains on the validation of the leaked data. While BleepingComputer noted a 21.5 GB Manchester customer export within the samples provided by the attackers, the full extent of the data's distribution online is still being monitored. Security experts expect this incident to prompt a wider audit of client-side JavaScript across major infrastructure providers to ensure that sensitive API keys are not inadvertently exposed to the public.