Airport operator refuses ransom, extortionists dump 8.8M records

FulcrumSec dumped MAG airport customer data after the operator refused a ransom, exposing 8.8 million people.

CSBadmin
2 Min Read

The extortion group behind the Manchester Airports Group intrusion has followed through on its threat, dumping roughly 550 GB of customer data after the airport operator refused to pay. Breach notification service Have I Been Pwned has processed the dataset and says it covers approximately 8.8 million email addresses and phone numbers, alongside names, IP addresses, purchase details, and vehicle registration plates.

MAG, which runs Manchester, London Stansted, and East Midlands airports, disclosed the intrusion August 27, saying attackers took customer information from a third-party database tied to car park, lounge, and Fast Track bookings and airport Wi-Fi sign-ups. Payment card data was not accessed.

FulcrumSec, the group claiming responsibility, says it pulled the data using Iterable administrator keys hardcoded into the frontend JavaScript of all three airport websites, a claim MAG has not confirmed. In its leak announcement, the group said it withheld the most dangerous material: nearly 200,000 passengers whose full upcoming travel schedules were in the stolen data, which it warned could feed burglary or stalking when linked to home addresses and vehicle details. It also claims the dataset includes thousands of government, judicial, military, police, NHS, and defense industry employees.

For affected travelers, the practical risk is targeted fraud. A criminal can now connect a person to an airport, a booking type, a car, and a contact number, making phishing about bookings, refunds, or parking penalties far more convincing. Anyone who used MAG’s parking, lounge, Fast Track, or Wi-Fi services should assume their details are circulating and check Have I Been Pwned.

Security teams watching the pattern should note the root cause: secrets left in client-side code. Organizations with web-facing booking or marketing platforms should audit JavaScript for embedded keys, rotate them regularly, and treat exposure in frontend code as a breach waiting to happen.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.