Aug 31, 2026 · 7 min read
Manchester Airports Breach Hits 8.7 Million Customers
Manchester Airports Group spotted the intrusion on 25 August 2026 and disclosed two days later. Extortion crew FulcrumSec then claimed 86 GB, including roughly 200,000 records for trips that have not happened yet.
Most breach datasets describe the past. This one has a calendar. Alongside the emails and phone numbers of 8.7 million Manchester, London Stansted and East Midlands customers, the attackers say they hold about 200,000 records for trips still to come in 2026, with dates, times and terminals attached to names. That is not a mailing list. It is a schedule.
Key Takeaways
- Manchester Airports Group confirmed on 27 August 2026 that an intruder accessed customer data across Manchester, London Stansted and East Midlands, affecting roughly 8.7 million people.
- MAG says the exposed fields are email addresses, phone numbers, vehicle registrations and postcodes, drawn from car park, lounge and Fast Track bookings and on airport Wi-Fi sign ups.
- MAG states that neither it nor the breached system holds bank or payment card details, and sample reviews have so far matched that.
- FulcrumSec told BleepingComputer it took about 86 GB using Iterable API credentials left in browser delivered JavaScript, which MAG has not addressed.
- The Information Commissioner's Office has MAG's breach report and is assessing it; the National Cyber Security Centre was also notified.
What Did Manchester Airports Group Actually Confirm?
MAG confirmed unauthorised access to customer information from car parking, lounge and Fast Track bookings and on airport Wi-Fi sign ups at its three airports. It became aware on 25 August 2026 and disclosed on 27 August. The Record reported the affected fields as email addresses, phone numbers, vehicle registrations and postcodes, with the intruder inside a few days before discovery.
On money MAG was direct: neither it nor the system reached holds bank or payment details. Manage My Booking was suspended as a precaution, reservations stayed valid, and changes inside 72 hours moved to phone. MAG emailed affected customers, warned them to expect phishing, and stressed it will never contact customers unexpectedly for card details. Its 8.7 million records are roughly one UK resident in eight against ONS estimates.
What Is FulcrumSec Claiming, and What Has Anyone Verified?
FulcrumSec claims roughly 86 GB, far richer than MAG's four field summary, and part of it has been checked. BleepingComputer reviewed samples containing booking references, pricing, parking dates and times, historical spend, IP addresses and device information, with no card or banking data. The sharpest item is a claimed 21.5 GB Manchester export plus about 200,000 records for travel across the rest of 2026.
One record was checked against a real purchase history and the Fast Track bookings, arrival times, terminals and amounts matched. MAG declined to address the claims, saying only that "we have contacted all those affected, including reaching out to all those with upcoming bookings." A ransom was reportedly demanded and refused. FulcrumSec says it will publish but may redact the upcoming travel records over the risk of "real-world harm." An extortion crew debating in public whether its own leak is too dangerous tells you more than any leak site figure.
How Do the Attackers Say They Got In?
FulcrumSec says it found airport specific Iterable API credentials sitting in client side JavaScript, code every visitor's browser downloads and anyone can read. Security Affairs reported the same account. MAG has neither confirmed nor denied it.
If accurate, this is not an exotic exploit but the oldest secrets management failure there is, the one OWASP devotes a whole cheat sheet to. What nobody has established is what those credentials permitted: export only, or sending too. Iterable is a customer engagement platform, the machinery marketing teams use to push email, so the gap between those answers is enormous. It fits the group's habits. FulcrumSec surfaced in October 2025 as a pure extortion operation, and its campaigns keep landing on the front end, from the JavaScript angle reported at Novo Nordisk to a vulnerable React application in its LexisNexis claim. One shape across three victims: the attack surface marketing owns, not the one security watches.

Why 200,000 Future Trips Is the Part That Matters
Because a record about the past ages badly and a record about next Thursday does not. When 12.9 million Carhartt customers had names, emails and home addresses dumped earlier in August, the danger was diffuse and open ended. Here it has a date on it. Someone who knows you land at Stansted on a Thursday at 06:40 knows when a message about that booking will feel true.
The offline half may be worse: a vehicle registration, a postcode and the dates that car sits in an airport car park is a statement about when a house is empty, and UK postcodes narrow to a handful of addresses. On timing MAG deserves credit, two days from discovery to disclosure against the three months Eurail took to tell 300,000 travellers their passport numbers were gone. But this exposure does not decay. It matures on a schedule the attacker can read.
What This Means for Your Inbox
Every affected customer received a genuine email from MAG warning them to watch for phishing. Right advice, and also the condition phishing feeds on: millions of people primed to expect unusual airport email. The NCSC's phishing guidance is worth reading before the first fake arrives.
The lures write themselves and guess nothing. "Your Fast Track booking on 14 September has been moved." "Your car park reservation could not be confirmed, please reconfirm your card." That second shape is what MAG pre empted by saying it will never contact customers unexpectedly for card details. Treat that as a rule, not reassurance. The fake cloud storage payment emails that flooded inboxes earlier this year converted on far less.
Then there is the entry point. If FulcrumSec's account holds, the compromised system was part of the email marketing stack itself, and nobody has said whether those credentials could send as well as read. Until MAG answers, treat any message carrying MAG branding as unverified and check bookings by opening the airport's own site.
What Is MAG's Exposure Under UK GDPR?
MAG reported the incident to the Information Commissioner's Office, which confirmed it has the report and is assessing it. Under UK GDPR a breach likely to risk people's rights and freedoms must be reported to the ICO within 72 hours, and where the risk is high the individuals told directly. MAG contacting customers with upcoming bookings is that second duty discharged in public.
The live question is Article 32, whether the measures were appropriate. If credentials for a third party platform were readable in page JavaScript, that is hard to defend against the ICO's own data security guidance. UK GDPR penalties top out at £17.5 million or 4% of global annual turnover, and outcomes land on the ICO's enforcement pages. The transferable audit item is cheap: inventory every marketing integration you ship to the browser and treat every key in it as public.
What Should Affected Travellers Do Right Now?
Assume inclusion. If you parked, booked a lounge or Fast Track, or used the Wi-Fi at any of the three airports, treat your details as in the file, then check where else that address appears at Have I Been Pwned.
- Verify any booking change message out of band: type the airport address in yourself, or ring the number on your confirmation.
- Never give card details in response to an unexpected email, text or call. MAG has said it will not ask.
- Expect calls and texts too. Phone numbers were in the confirmed data classes.
- Treat your vehicle registration as public. A message quoting it back proves nothing about who sent it.
- Turn on two factor authentication anywhere that address is a login, starting with the email account.
- Report suspicious UK messages to the NCSC's Suspicious Email Reporting Service at report@phishing.gov.uk.
One last thing: do not act on an unprompted breach notice arriving right after you read about the breach. Fakes follow real ones within days, and work because you were told to expect one.