Zero Day Room
Live
Threats

FulcrumSec Leaks 550GB of Manchester Airport Group Data

The FulcrumSec threat group claims to have leaked 550GB of stolen customer data from the Manchester Airports Group, alleging initial access via exposed

The FulcrumSec threat group claims to have leaked 550GB of stolen customer data from the Manchester Airports Group...

The FulcrumSec threat group has posted approximately 550GB of data it claims to have stolen from the Manchester Airports Group (MAG). The group alleges the data comprises nearly pure personally identifiable information (PII) from MAG customers.

According to a post on its leak site, FulcrumSec states it obtained initial access by discovering admin keys for the customer engagement platform Iterable. The group claims these keys were embedded in the frontend JavaScript code on the root domains of all three MAG airport websites: Manchester Airport, Stansted Airport, and East Midlands Airport. "Any of the millions of visitors to the site could have right-clicked 'inspect' and seen the keys just sitting there, plain as day," FulcrumSec wrote in its note.

Scope of the Exfiltrated Data

The leaked data reportedly includes a broad sweep of customer information. FulcrumSec claims to have exfiltrated nearly 8.7 million customer profiles containing email addresses, names, mobile numbers, home towns, postcodes, and residential IP addresses. This data could enable convincing follow-on phishing attacks against the victims.

The group also alleges the breach captured extensive marketing and transactional records.

Data TypeQuantity
Customer ProfilesNearly 8.7 million
Marketing Events (sends, opens, clicks)Nearly 1.2 billion
Purchases (parking, Fast Track, lounge bookings)Nearly 2.5 million
SMS Messages (with booking date, car park, vehicle reg)Over 461,000
Unique Vehicle Registration Plates108,000
Future BookingsNearly 191,000

Additionally, platform configuration data was reportedly swept up in the breach.

Risks of Physical Targeting

FulcrumSec highlighted a specific physical security risk from the data on nearly 191,000 future bookings. This information includes travel schedules, PII, and vehicle details that the group claims could be used by criminals to target holidaymakers' homes while they are away. The group suggested that some affected individuals, judged by their email addresses, are likely public figures, politicians, and military staff.

MAG's Response and Ransom Demand

FulcrumSec claimed MAG declined to pay a ransom to prevent the data leak. "Sadly MAG declined to pay the necessary fee to protect their passengers' data, leaving us to remove the most sensitive parts..." the group stated. The claims made by FulcrumSec have not been independently verified. MAG has not provided any public update on the incident since its original statement on August 27, leaving the full scope and impact of the breach unconfirmed.

The group's post attempts to shed more light on an incident about which limited information has been available. FulcrumSec also referenced its previous breaches of Arup Group and Novo Nordisk, contrasting the MAG access method as not requiring subdomain enumeration.

Topics

#Threats

Related coverage

More from Threats