INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Manchester Airports Group Data Leaked to Crooks Behind Hackers

| 2026-09-04 18:30 CRITICAL LOW DATA BREACH CRITICAL INFRASTRUCTURE & OT
Executive Summary
AI-generated
On September 4, 2026, Manchester Airports Group (MAG) confirmed a data breach involving customer information held in a third-party database, exposing emails and phone numbers of approximately 8.8 million people. The attackers, identified as FulcrumSec, gained access to MAG's systems using administrator keys exposed in the JavaScript code of its three airport websites, which were hardcoded into each site. This allowed them to obtain data on customer profiles, events, and configurations for all passengers who had passed through those airports, including 2.5 million purchases, 461,433 SMS messages, and 108,077 unique UK vehicle registration plates tied to the owner's email and mobile numbers. The leaked data includes information such as emails, phone numbers, home towns, postal regions, residential IP addresses, and payment-card details for parking, lounge, and Fast Track bookings, as well as airport Wi-Fi sign-ups.
Technical Mitigations AI-generated
• Rotate administrator keys regularly to prevent exposure in client-side code. • Limit access to sensitive data and systems, especially for third-party databases. • Scan code, repositories, logs, and configurations for accidental exposure of secrets.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

st•••••.com
ma•••••.uk
ea•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORTH_AMERICA NORTH_AMERICA aviationaviation
Incident Timeline
‎2026/09/04
Threat actors behind the Manchester Airports Group hack leaked sensitive data, including customer profiles and transactions, of 8.8 million people in plain text.
financial 461,433 £ SMS messages
‎September 04, 2026
Threat actors accessed Manchester Airports Group's systems using administrator keys exposed in the JavaScript of its three airport websites.
data_breach 550 GB
Tactical Metrics
Metrics
financial
461,433
£ Sms Messages
Metrics
data_breach
550
Gb
Intelligence Sources