// 2 ZERO-DAY · 3 CVE · 5 EXPLOIT IN THE LAST 24H
The FulcrumSec data extortion group claimed responsibility for the Manchester Airports Group breach, publishing ~86 GB of data. Access was gained via Iterable API credentials hardcoded in the client-side JavaScript across all three airport websites.

On August 27, 2026, Manchester Airports Group (MAG) disclosed a customer data theft. In the following week, the data extortion group FulcrumSec claimed responsibility, publishing ~86 GB of materials on a leak site and detailing an access vector as trivial as it was severe: API credentials for the Iterable customer engagement platform, hardcoded in the client-side JavaScript of all three group airport websites.

Key Takeaways
  • FulcrumSec claimed responsibility for the MAG breach, asserting it stole ~86 GB of data (~549 GB uncompressed) covering ~8.7 million customer profiles.
  • The group says it gained access via Iterable API credentials exposed in client-side JavaScript on the public root domains of Manchester, Stansted, and East Midlands airports.
  • BleepingComputer validated the authenticity of at least one record by cross-referencing a traveler's known purchase history, confirming the plausibility of the samples.
  • MAG confirmed ~8.7 million affected customers but stated that for the "vast majority" only email addresses were exposed; the group, by contrast, reports detailed PII, upcoming bookings, and vehicle data.

How the Attack Works: The Frontend as a Forgotten Perimeter

The API credentials were embedded directly in the JavaScript code served to users' browsers. According to FulcrumSec's claim, reported by InfoSecurity Magazine, "all three of these were on the sites' root domain... any of the millions of visitors to the site could have right-clicked 'inspect' and seen the keys just sitting there, plain as day." This exposure required no sophisticated exploit: simply visit the page, open browser developer tools, and read the source.

Iterable API keys, a marketing automation and customer engagement platform, granted access to consolidated datasets merging demographic profiles, purchase history, marketing events, and behavioral predictions. The technical crux lies in the access category: platforms of this type are often classified as "marketing" and therefore subject to less stringent controls than payment or operational management systems, despite containing highly sensitive data.

Traditional controls such as Web Application Firewalls (WAF) and Content Security Policy (CSP) do not detect the exposure of secrets in client-side source code: the traffic is legitimate, the origin is the official server, the content is valid JavaScript. The gap is in the code deployment and review phase, not in runtime perimeter protection.

What the Stolen Data Contains: Profiles, Bookings, and Plaintext Messages

FulcrumSec provided BleepingComputer with granular details on the dataset composition. The materials reportedly include ~8.7 million customer profiles with email, name, mobile number, city, postal code, and residential IP address. These are joined by ~1.2 billion marketing events (sends, opens, clicks), ~2.5 million historical purchases related to airport services (parking, Fast Track, lounge), and ~461,000 SMS messages with booking details in plaintext.

A particularly sensitive component, not independently verified, concerns ~191,000 upcoming bookings with travel schedules, detailed PII, and vehicle data. BleepingComputer reports a slightly different figure (~200,000 records related to future 2026 travel), explicitly stating it could not confirm this portion of the claim. The source was unable to independently verify "the full extent of the access or the exact amount of data stolen."

BleepingComputer did, however, validate a specific record by comparing it against a real traveler's known purchase history: the details matched, confirming at least partial authenticity of the samples provided by the group. No payment information emerged from the reviewed materials, consistent with MAG's statement.

"These keys were not found on some obscure subdomain... All three of these were on the sites' root domain... any of the millions of visitors to the site could have right-clicked 'inspect' and seen the keys just sitting there, plain as day." — FulcrumSec, quoted by InfoSecurity Magazine

MAG's Response: Ransom Refusal and Disclosure Limits

MAG received a ransom demand and refused to pay, according to SecurityWeek. In a statement cited by BleepingComputer, a group spokesperson said: "MAG is confident it has taken effective measures to protect customers and has contacted all those affected, including those with upcoming bookings, to inform them of the additional support available." The "Manage My Booking" service was suspended on August 27.

MAG's official disclosure, also dated August 27, confirmed the theft of data from parking, lounge, Fast Track bookings, and Wi-Fi registrations, but did not specifically confirm or deny the access method via Iterable credentials. The spokesperson cited by BleepingComputer confirmed the ~8.7 million affected customers, specifying that for the "vast majority" only email addresses were exposed. This discrepancy between the group's claim and the official confirmation remains unresolved: MAG has not publicly verified the full extent of the detailed PII reported by FulcrumSec.

Neither MAG nor security sources detected operational disruptions or compromise of aviation safety systems. The breach is confined to customer engagement and marketing data.

Who Is FulcrumSec: Pattern and Confirmed Precedents

FulcrumSec is a data extortion group active since 2025, operating a model that does not involve encrypting victim systems but focuses on stealing and threatening to publish sensitive data. BleepingComputer documents previous attacks on LexisNexis, Novo Nordisk, Global Schools Group, and Avnet, confirming consistent patterns: AWS infrastructure, publication on a proprietary leak site, and victims refusing to pay the ransom.

In the MAG case, FulcrumSec claimed to have "removed the most sensitive parts" before publishing on the leak site, adding: "Unfortunately MAG declined to pay the amount needed to protect passenger data, leaving us with the responsibility of removing the most sensitive parts... before publication." This statement, reported by InfoSecurity Magazine, is not independently verifiable: available sources do not indicate whether the removal actually occurred or what criteria were applied.

No infrastructure overlaps link FulcrumSec to known ransomware groups or state-attributed operators at this time. The dossier does not specify whether other actors or individuals may have had access to the same API credentials before the group.

Why This Matters

The MAG case exemplifies a systematically underestimated security pattern: the classification of customer engagement SaaS platforms as "non-critical" security perimeter, despite managing data enabling extremely granular profiling. An Iterable API key, considered "read-only" or limited to marketing, can exfiltrate datasets combining future movements, consumption preferences, demographics, and persistent identifiers: material sufficient for personalized phishing campaigns or, in extreme cases, physical targeting.

The dossier does not specify whether public figures, military personnel, or politicians are present in the data. It does not document specific remedial measures adopted by MAG for API credential management. It does not specify the exact nature of the vehicle data included in the samples. The precise timeline of the intrusion and discovery is not declared by sources.

For travelers, the immediate risk is not financial compromise — explicitly excluded — but the precision of data available to malicious actors: bookings with dates, terminals, purchased services, and, according to the group's claim, vehicle license plates. This profile enables contextualized phishing on real trips, with conversion rates typically higher than generic campaigns.

For the airport sector, this represents the largest known customer data breach of a UK operator, measured by the ~8.7 million confirmed records. The measure is not volume alone, but the combination of predictive accuracy (future bookings) and profiling completeness that marketing engagement platforms consolidate.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. infosecurity-magazine.com
  2. bleepingcomputer.com
  3. securityweek.com
  4. we-fix-pc.com
  5. circleid.com
  6. podcast.securityweek.com