The extortion group FulcrumSec has claimed responsibility for the August data breach at Manchester Airports Group (MAG), the largest airport operator in the United Kingdom, stating that it stole roughly 86 GB of data. MAG, which operates Manchester, London Stansted, and East Midlands airports, disclosed on August 27 that an unauthorized party had accessed customer data tied to car park, lounge, and Fast Track bookings, as well as in-airport Wi-Fi registrations. FulcrumSec provided BleepingComputer with sample files that appeared to show significantly more detailed customer, booking, and travel information than MAG initially acknowledged.
BleepingComputer verified one sample record against a traveller's known purchase history, confirming details such as previous Fast Track purchases, booking times, terminals used, amounts paid, and trip purposes. The leaked material included a roughly 21.5 GB export of Manchester customer profiles that combined identifiers with historical booking activity and marketing classifications. FulcrumSec said it gained access using airport-specific Iterable API credentials exposed in client-side JavaScript and claimed the stolen data includes nearly 200,000 records related to upcoming travel through the rest of 2026, containing dates, times, and booking details linked to personally identifiable information.
Beyond the email addresses, phone numbers, vehicle registrations, and postcodes that MAG disclosed, the sampled records contained purchase references, airport and product selections, prices, discounts, booking status, parking dates and times, historical spending, IP addresses, approximate locations, and device information. BleepingComputer did not observe payment-card or bank-account data in the samples it reviewed. The publication stated it deleted all supplied material after verification and will not publish any part of it, nor could it independently confirm the full extent of the theft or the claim about upcoming-travel records.
FulcrumSec, a financially motivated data-extortion group active since 2025, typically steals sensitive corporate data and threatens to publish it rather than encrypting systems. The group has previously claimed attacks on LexisNexis, Novo Nordisk, Global Schools Group, and Avnet. FulcrumSec told BleepingComputer it intends to publish the stolen data and a technical account of the intrusion but is considering withholding or redacting the upcoming-travel records due to the potential for real-world harm.
BleepingComputer contacted MAG again before publication, asking the company to address the claims about the 86 GB dataset, the exposed credentials, and the future-travel data. A MAG spokesperson declined to address those specific claims, instead referring to an updated statement confirming that affected customers with upcoming bookings had been contacted. The spokesperson said MAG is confident it has taken effective measures to protect customers and has reached out to all those affected, including those with upcoming bookings, to advise them of additional support.
For US technology and security readers, the risk profile is notable because a full UK postcode can pinpoint roughly 15 addresses, with some assigned to a single property, unlike broader US ZIP codes. Combined with contact, vehicle, and travel details, attackers could craft convincing phishing emails, texts, or phone scams impersonating MAG or a booking provider. MAG has advised affected customers to remain vigilant for suspicious communications and stressed that it would never contact customers unexpectedly to request payment-card details, banking information, or passwords.
More cybersecurity news from TechManNews.







