Manchester Airports Group (MAG) disclosed that customer data linked to Manchester, Stansted and East Midlands airports was accessed and later published by the FulcrumSec extortion group after reported ransom negotiations failed. The incident affects roughly 8.7–8.8 million people using parking, lounge, Fast Track and airport Wi-Fi services; exposed records reportedly include contact details, vehicle-registration and postcode information, booking history, and some upcoming 2026 travel records. MAG said airport operations, aviation security and passenger safety were not affected, and the UK ICO is assessing its breach notification.
FulcrumSec said it obtained MAG’s Iterable server-side API credentials from publicly accessible Next.js JavaScript bundles, not through a conventional network intrusion. The credentials were reportedly exposed from mid-2022 until August 2026 and could enable bulk customer-data exports as well as potentially destructive user-management API actions; independent researcher Scott Helme said he verified the technical basis of the claim. Organizations should ensure server-side API keys are never embedded in client-delivered code, rotate exposed credentials, review third-party SaaS audit logs, and assess data-access and account-management activity for affected integrations.

See attribution, scope, and your downstream exposure.
10 events from the most recent confirmed update back to the earliest known activity.
Scott Helme published a technical analysis reporting that he verified FulcrumSec's central claim that publicly exposed Iterable server-side API keys enabled access to MAG customer data. The keys reportedly permitted broad API access, including user-profile retrieval and database exports.
MAG announced a breach of its internal network affecting data associated with Manchester, Stansted, and East Midlands airports. It said the compromised data related to parking, lounges, Fast Track, and in-airport Wi-Fi services, while airport operations, aviation security, passenger safety, and parking facilities were unaffected.
The Stansted Airport Iterable key was reportedly publicly exposed through 23 August 2026.
The Manchester Airport Iterable key was reportedly publicly exposed through 22 August 2026.
The East Midlands Airport Iterable key was reportedly publicly exposed through 16 August 2026. Wayback Machine history was used to establish the approximate exposure period.
A Manchester Airport-specific Iterable server-side API key was reportedly exposed in a publicly accessible Next.js JavaScript bundle beginning on 11 July 2022.
A separate Iterable server-side API key in Stansted Airport's public JavaScript bundle was reportedly exposed beginning on 28 June 2022.
An Iterable server-side API key in East Midlands Airport's public Next.js JavaScript bundle was reportedly exposed beginning on 23 June 2022.
MAG formally notified the UK Information Commissioner's Office of the incident. The ICO said it was assessing the nature and extent of the exposed information to determine whether further action was needed.
FulcrumSec claimed responsibility for the incident and published what it described as MAG's full stolen dataset after ransom negotiations allegedly failed. The group alleged it had obtained data through the exposed Manchester Airport Iterable credentials, including future-travel records and personally identifiable information.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourceteiss.co.uk
Open sourcescotthelme.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.