Manchester Airports Breach Exposes 8.8M Users After Ransom Refusal
The Manchester Airports Group (MAG) has confirmed that approximately 8.8 million individuals had their personal data exposed after the FulcrumSec extortion gang published roughly 550 gigabytes of stolen information online over the weekend. MAG, which operates Manchester, London Stansted, and East Midlands airports, disclosed the breach last week, warning that hackers had exfiltrated car park, lounge, and Fast Track booking data, along with in-airport Wi-Fi sign-ups. According to HaveIBeenPwned, which parsed the dataset and added it to its tracking database, the leaked records include approximately 8.8 million unique email addresses and phone numbers, in addition to names, browser user-agent strings, vehicle registration plates, and residential IP addresses tied to user accounts.
FulcrumSec claims the stolen cache contains 2,482,763 purchase records, 461,433 SMS messages linked to bookings, and 108,077 unique UK vehicle registration plates. The extortion group also alleges it exfiltrated MAG platform configuration data. According to FulcrumSec, the initial access vector was shockingly straightforward: admin keys were left exposed in plain text within the frontend JavaScript of each of MAG's three airport websites' root domains. MAG confirmed the stolen information was stored in a third-party hosted database and that it received a ransom demand, which it refused. Users concerned about exposure can verify their credentials using a email breach checker and should immediately update any reused passwords via a password checker to confirm credential strength.
The incident underscores how exposed client-side code can serve as a low-effort entry point for large-scale data theft. With residential IP addresses, browser fingerprints, and contact details now circulating publicly, affected travelers face elevated risks of targeted phishing, SIM-swap attempts, and account takeover. SecurityWeek has not independently verified FulcrumSec's full claims, but the volume of leaked records and MAG's confirmation of refused ransom payment align with the gang's narrative. Individuals impacted should run a privacy checkup to review their digital exposure, monitor financial accounts for suspicious activity, and enable multi-factor authentication wherever possible to mitigate downstream risks from this breach.