INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Manchester Airports Group Data Leaked to Crooks Behind Hackers
| 2026-09-04 18:30 CRITICAL LOW DATA BREACH CRITICAL INFRASTRUCTURE & OT
Executive Summary
AI-generated
On September 4, 2026, Manchester Airports Group (MAG) confirmed a data breach involving customer information held in a third-party database, exposing emails and phone numbers of approximately 8.8 million people. The attackers, identified as FulcrumSec, gained access to MAG's systems using administrator keys exposed in the JavaScript code of its three airport websites, which were hardcoded into each site. This allowed them to obtain data on customer profiles, events, and configurations for all passengers who had passed through those airports, including 2.5 million purchases, 461,433 SMS messages, and 108,077 unique UK vehicle registration plates tied to the owner's email and mobile numbers. The leaked data includes information such as emails, phone numbers, home towns, postal regions, residential IP addresses, and payment-card details for parking, lounge, and Fast Track bookings, as well as airport Wi-Fi sign-ups.
Technical Mitigations AI-generated
• Rotate administrator keys regularly to prevent exposure in client-side code.
• Limit access to sensitive data and systems, especially for third-party databases.
• Scan code, repositories, logs, and configurations for accidental exposure of secrets.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
st•••••.com
ma•••••.uk
ea•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
aviationaviation
Incident Timeline
2026/09/04
Threat actors behind the Manchester Airports Group hack leaked sensitive data, including customer profiles and transactions, of 8.8 million people in plain text.
Click on any entity below to view its context and source!
financial
461,433 £ SMS messages
An analysed subset of 1,154,675 transactions, from 877,754 identified purchasers, totals £83,413,317.89
461,433 SMS messages
rendered with a passenger’s booking date, car park and vehicle registration spelled out in plain text
108,077 unique UK…
September 04, 2026
Threat actors accessed Manchester Airports Group's systems using administrator keys exposed in the JavaScript of its three airport websites.
Click on any entity below to view its context and source!
data_breach
550 GB
The group then published roughly 550 GB of uncompressed data it says came from the airport operator’s systems.
Tactical Metrics
Metrics
financial
461,433
£ Sms Messages
Click for context!
An analysed subset of 1,154,675 transactions, from 877,754 identified purchasers, totals £83,413,317.89
461,433 SMS messages
rendered with a passenger’s booking date, car park and vehicle registration spelled out in plain text
108,077 unique UK…
Metrics
data_breach
550
Gb
The group then published roughly 550 GB of uncompressed data it says came from the airport operator’s systems.
Intelligence Sources
Security Affairs
2026-09-04
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T10:39
Comprehensive Tactical Telemetry
Highly Correlated Entities
14x
organisation
Identified Entity
London Stansted
entity
4x
tactic
Cyber Operation Type
Data Breach
tactic
3x
timeline
Temporal Reference
September 04, 2026
date
2x
industry
Targeted Sector
Aviation
sector
Contextual Telemetry
Context Block
13 METRICS
target region
Target Country
United States
country
source region
Origin Country
United Kingdom
country
general metric
Transactions
1,154,675
transactions
general metric
Identified Purchasers
877,754
identified purchasers
financial
£ Sms Messages
461,433
£ sms messages
general metric
Text Unique Registration Plates
108,077
text unique registration plates
attribution
Attributing Entity
NHS
authority
tactic
MITRE ATT&CK Technique
T1059.007 - JavaScript
technique
general metric
Pierluigi Paganini
8,800,000
pierluigi paganini
general metric
Passengers
200,000
passengers
data breach
Gb
550
gb
general metric
Future Bookings
190,849
future bookings
general metric
Bookings
142,755
bookings
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.