FulcrumSec Leaks About 550 GB of Manchester Airports Group Data Affecting Roughly 8.8 Million People
Extortion group FulcrumSec leaked about 550 GB of Manchester Airports Group data after a refused ransom, exposing roughly 8.8 million email addresses and phone numbers, 108,077 vehicle registration plates, 2.48 million purchases and 1.16 billion email events;…
Manchester Airports Group, operator of Manchester, London Stansted and East Midlands airports, confirmed a breach of a third-party database after extortion group FulcrumSec leaked roughly 550 GB of data following a refused ransom. The exposed data includes about 8.8 million email addresses and phone numbers, 108,077 vehicle registration plates, 2.48 million purchases and 1.16 billion email events, plus postcodes and IPs; MAG says no payment-card data was accessed. About 190,849 future bookings exposing travel schedules create burglary and stalking risks. FulcrumSec claims it gained access using Iterable admin keys hardcoded in the frontend JavaScript of all three airport websites; MAG has not confirmed this claim, so it remains unverified. MAG disclosed the incident on August 27, said it contained the risk, and notified authorities, and Have I Been Pwned added the incident to its breach database. Separately, Troy Hunt's roundup (not MAG-specific) stressed that breach claims require verification, citing ShinyHunters' unverified claim of a 50 GB Carhartt breach with millions of records, and reported Sri Lanka CERT as the 48th government onboarded to HIBP's free breach-monitoring service, following Nepal as the 47th.
- MAG, operator of Manchester, London Stansted and East Midlands airports, confirmed a breach of a third-party database; FulcrumSec leaked roughly 550 GB after a refused ransom.
- Exposed data: about 8.8 million email addresses and phone numbers, 108,077 vehicle registration plates, 2.48 million purchases, 1.16 billion email events, postcodes and IPs; no payment-card data accessed.
- About 190,849 future bookings exposed travel schedules, creating burglary and stalking risks.
- FulcrumSec claims it used Iterable admin keys hardcoded in the frontend JavaScript of all three airport websites; MAG has not confirmed this, so the access method is unverified.
- MAG disclosed the incident on August 27, said it contained the risk, and notified authorities.
- Have I Been Pwned added the incident to its breach database.
- Related, from Troy Hunt's roundup (separate items): Sri Lanka CERT became the 48th government onboarded to HIBP's free breach-monitoring service, following Nepal as the 47th; ShinyHunters' claim of a 50 GB compressed Carhartt breach with…
Coverage timelineoldest first · each row is one article
- · 11d agoCrooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People
Security Affairs· 84
FulcrumSec leaked about 550 GB of Manchester Airports Group data, exposing emails, phones and vehicle registrations of roughly 8.8 million people after a refused ransom.