Manchester Airports Group Breach: FulcrumSec Claims 86GB Data Theft, Scope Wider Than Initially Disclosed
The **Manchester Airports Group (MAG)**, the UK's largest airport operator, is reeling from a significant data breach. Extortion group **FulcrumSec** has claimed responsibility, alleging the theft of approximately 86 GB of sensitive customer data, including detailed booking and travel information, which appears to be far more extensive than MAG's initial disclosures.

**Manchester Airports Group (MAG)**, the operator behind **Manchester**, **London Stansted**, and **East Midlands** airports, initially disclosed a data breach on August 27. The company stated that an unauthorized third party had accessed customer data related to car park, lounge, and Fast Track bookings, as well as in-airport Wi-Fi registrations.
## FulcrumSec Claims Massive Data Haul
Extortion group **FulcrumSec** has since come forward, claiming responsibility for the attack and the theft of approximately 86 GB of data. Samples provided to BleepingComputer by **FulcrumSec** were consistent with **MAG**'s disclosure but suggested a considerably broader exposure of customer, booking, and travel information than initially revealed.
One record validated by BleepingComputer accurately detailed a traveler's previous Fast Track purchases, including booking and scheduled arrival times, terminal used, amounts paid, purchase references, total spending, and apparent trip purpose.
## Deep Dive into the Stolen Data
The stolen material reportedly includes a 21.5 GB export of **Manchester** customer profiles, consolidating identifiers with historical booking activity and marketing classifications. **FulcrumSec** claims to have gained access via airport-specific **Iterable API** credentials exposed in client-side JavaScript.
The group also asserts that the stolen data encompasses nearly 200,000 records related to upcoming travel through 2026, containing dates, times, and booking information linked to personally identifiable information. While BleepingComputer could not independently verify the full extent of the access or the size of the dataset, the samples appeared authentic.
**FulcrumSec**, active since 2025, is a financially motivated data-extortion group that specializes in stealing sensitive corporate data and threatening its publication, rather than encrypting systems. The group has previously claimed attacks on organizations such as **LexisNexis**, **Novo Nordisk**, **Global Schools Group**, and **Avnet**.
## MAG's Response and Broader Implications
When contacted, **MAG** declined to address **FulcrumSec**'s specific claims regarding the 86 GB dataset, exposed credentials, or future travel data. A spokesperson referred to an updated statement confirming that affected customers with upcoming bookings had been contacted and advised of additional support. **MAG** is understood to have refused to pay a monetary ransom reportedly demanded by the attackers.
Beyond the email addresses, phone numbers, vehicle registrations, and postcodes initially disclosed, the sampled records contained purchase and booking references, airport and product selections, prices, discounts, booking status, parking dates and times, historical spending, IP addresses, approximate locations, device information, and customer-engagement data. Notably, payment card or bank account information was not observed in the reviewed samples.
The combination of contact, vehicle, and travel information, especially with the precision of UK postcodes (which can identify as few as 15 addresses or even a single one), could enable attackers to craft highly convincing phishing emails, text messages, or telephone scams impersonating **MAG** or booking providers.
**MAG** has advised affected customers to remain vigilant for suspicious communications, emphasizing that the airport operator would never unexpectedly request payment card details, banking information, or passwords. The incident has not caused operational disruption, and **MAG** states that passenger safety and aviation security were not compromised.
Previously, **MAG** indicated that around 8.7 million customers were affected, though for the vast majority, only email addresses were exposed. This makes it the largest known customer data breach affecting a British airport operator.