ZeroHour
Story · 1 source · 1 articlefirst updated ()

FulcrumSec Leaks About 550 GB of Manchester Airports Group Data Affecting Roughly 8.8 Million People

criticalData breachimportance 84
What's new: First merged summary (no previous summary existed). Newly consolidated: full details of the MAG/FulcrumSec leak (about 550 GB; 8.8 million email addresses and phone numbers; 108,077 vehicle plates; 2.48 million purchases; 1.16 billion email events; 190,849 future bookings), the unverified hardcoded Iterable keys claim, the August 27 disclosure and authority notification, and the incident's…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Extortion group FulcrumSec leaked about 550 GB of Manchester Airports Group data after a refused ransom, exposing roughly 8.8 million email addresses and phone numbers, 108,077 vehicle registration plates, 2.48 million purchases and 1.16 billion email events;…

Manchester Airports Group, operator of Manchester, London Stansted and East Midlands airports, confirmed a breach of a third-party database after extortion group FulcrumSec leaked roughly 550 GB of data following a refused ransom. The exposed data includes about 8.8 million email addresses and phone numbers, 108,077 vehicle registration plates, 2.48 million purchases and 1.16 billion email events, plus postcodes and IPs; MAG says no payment-card data was accessed. About 190,849 future bookings exposing travel schedules create burglary and stalking risks. FulcrumSec claims it gained access using Iterable admin keys hardcoded in the frontend JavaScript of all three airport websites; MAG has not confirmed this claim, so it remains unverified. MAG disclosed the incident on August 27, said it contained the risk, and notified authorities, and Have I Been Pwned added the incident to its breach database. Separately, Troy Hunt's roundup (not MAG-specific) stressed that breach claims require verification, citing ShinyHunters' unverified claim of a 50 GB Carhartt breach with millions of records, and reported Sri Lanka CERT as the 48th government onboarded to HIBP's free breach-monitoring service, following Nepal as the 47th.

  • MAG, operator of Manchester, London Stansted and East Midlands airports, confirmed a breach of a third-party database; FulcrumSec leaked roughly 550 GB after a refused ransom.
  • Exposed data: about 8.8 million email addresses and phone numbers, 108,077 vehicle registration plates, 2.48 million purchases, 1.16 billion email events, postcodes and IPs; no payment-card data accessed.
  • About 190,849 future bookings exposed travel schedules, creating burglary and stalking risks.
  • FulcrumSec claims it used Iterable admin keys hardcoded in the frontend JavaScript of all three airport websites; MAG has not confirmed this, so the access method is unverified.
  • MAG disclosed the incident on August 27, said it contained the risk, and notified authorities.
  • Have I Been Pwned added the incident to its breach database.
  • Related, from Troy Hunt's roundup (separate items): Sri Lanka CERT became the 48th government onboarded to HIBP's free breach-monitoring service, following Nepal as the 47th; ShinyHunters' claim of a 50 GB compressed Carhartt breach with…

Coverage timeline

  1. · 11d ago
    Security Affairs· 84
    Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People

    FulcrumSec leaked about 550 GB of Manchester Airports Group data, exposing emails, phones and vehicle registrations of roughly 8.8 million people after a refused ransom.