FulcrumSec Leaks 550GB of Manchester Airport Group Data
The FulcrumSec threat group claims to have leaked 550GB of stolen customer data from the Manchester Airports Group, alleging initial access via exposed

The FulcrumSec threat group has posted approximately 550GB of data it claims to have stolen from the Manchester Airports Group (MAG). The group alleges the data comprises nearly pure personally identifiable information (PII) from MAG customers.
According to a post on its leak site, FulcrumSec states it obtained initial access by discovering admin keys for the customer engagement platform Iterable. The group claims these keys were embedded in the frontend JavaScript code on the root domains of all three MAG airport websites: Manchester Airport, Stansted Airport, and East Midlands Airport. "Any of the millions of visitors to the site could have right-clicked 'inspect' and seen the keys just sitting there, plain as day," FulcrumSec wrote in its note.
Scope of the Exfiltrated Data
The leaked data reportedly includes a broad sweep of customer information. FulcrumSec claims to have exfiltrated nearly 8.7 million customer profiles containing email addresses, names, mobile numbers, home towns, postcodes, and residential IP addresses. This data could enable convincing follow-on phishing attacks against the victims.
The group also alleges the breach captured extensive marketing and transactional records.
| Data Type | Quantity |
|---|---|
| Customer Profiles | Nearly 8.7 million |
| Marketing Events (sends, opens, clicks) | Nearly 1.2 billion |
| Purchases (parking, Fast Track, lounge bookings) | Nearly 2.5 million |
| SMS Messages (with booking date, car park, vehicle reg) | Over 461,000 |
| Unique Vehicle Registration Plates | 108,000 |
| Future Bookings | Nearly 191,000 |
Additionally, platform configuration data was reportedly swept up in the breach.
Risks of Physical Targeting
FulcrumSec highlighted a specific physical security risk from the data on nearly 191,000 future bookings. This information includes travel schedules, PII, and vehicle details that the group claims could be used by criminals to target holidaymakers' homes while they are away. The group suggested that some affected individuals, judged by their email addresses, are likely public figures, politicians, and military staff.
MAG's Response and Ransom Demand
FulcrumSec claimed MAG declined to pay a ransom to prevent the data leak. "Sadly MAG declined to pay the necessary fee to protect their passengers' data, leaving us to remove the most sensitive parts..." the group stated. The claims made by FulcrumSec have not been independently verified. MAG has not provided any public update on the incident since its original statement on August 27, leaving the full scope and impact of the breach unconfirmed.
The group's post attempts to shed more light on an incident about which limited information has been available. FulcrumSec also referenced its previous breaches of Arup Group and Novo Nordisk, contrasting the MAG access method as not requiring subdomain enumeration.





