Manchester Airports Group (MAG), which operates Manchester, London Stansted, and East Midlands airports, disclosed a breach affecting approximately 8.7 million customers. The exposed data primarily came from airport Wi-Fi registrations and parking, lounge, and Fast Track booking services; MAG temporarily suspended its online Manage My Booking service. The company said passenger safety, aviation security, and flight operations were not affected.
The FulcrumSec data-extortion group claimed it exfiltrated roughly 86 GB of data using airport-specific Iterable API credentials exposed in client-side JavaScript. Stolen contact, travel, and vehicle-related data could support targeted phishing and smishing campaigns, identity fraud, extortion, and potential intelligence collection against travelers.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
FulcrumSec claimed it stole approximately 86 GB of MAG data by exploiting airport-specific Iterable API credentials exposed in client-side JavaScript. The group said the material included contact, postcode, vehicle-registration, and travel data, including nearly 200,000 records for travel scheduled during the rest of 2026.
Manchester Airports Group disclosed a data breach reportedly affecting about 8.7 million customers, primarily involving email addresses from airport Wi-Fi registrations as well as parking, lounge, and Fast Track booking data. MAG temporarily suspended its Manage My Booking service and said passenger safety, aviation security, and flight operations were unaffected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceblog.bushidotoken.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.