AUTO-UPDATED

Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft

Manchester Airports Group confirmed a data breach affecting 8.7 million customers across three major UK airports, while an extortion group claims to have stolen significantly more sensitive information.

Key Points

  • The breach impacts customers of Manchester, London Stansted, and East Midlands airports who used parking, lounge, or WiFi services.
  • Manchester Airports Group (MAG) states exposed data includes email addresses, phone numbers, vehicle registrations, and postcodes.
  • The extortion group FulcrumSec claims to have stolen 86GB of data, including detailed travel itineraries and booking history.
  • Attackers allegedly accessed the system by exploiting Iterable API credentials left exposed within the website's client-side JavaScript code.
  • Reports indicate approximately 200,000 records contain specific travel dates and times for trips scheduled through the end of 2026.

Why it Matters

This incident highlights the significant security risks associated with relying on third-party platforms and the dangers of exposing sensitive API credentials in client-side code. The combination of precise UK postcode data and specific travel itineraries creates a high risk for sophisticated, targeted phishing attacks against affected passengers.
Securityaffairs.com Published by Pierluigi Paganini
Read original