Manchester Airports Group Data Allegedly Leaked Following Ransom Demand

Manchester Airports Group (MAG) says a cyber incident exposed customer information connected to parking, lounge and Fast Track bookings, as well as airport Wi-Fi registrations. The operator said the e...

Manchester Airports Group (MAG) says a cyber incident exposed customer information connected to parking, lounge and Fast Track bookings, as well as airport Wi-Fi registrations. The operator said the event did not disrupt operations at Manchester, London Stansted or East Midlands airports.

The incident has since been claimed by the FulcrumSec extortion group, which says it published about 550GB of data after MAG declined to pay a ransom. The group’s claims, including the amount and scope of material taken, have not been independently verified.

Millions of records reportedly affected

MAG previously said the compromised information included email addresses, telephone numbers, vehicle registration details and postcodes. The company said the affected data was held in a database operated by a third party, but did not provide further details about the ransom demand or the supplier involved.

FulcrumSec alleges that the leaked material contains personal data associated with roughly 8.7 million people. Breach-notification service Have I Been Pwned reported that it analyzed the dataset and added approximately 8.8 million email addresses and phone numbers to its notification database.

According to the group and the breach-notification service, the data may include names, email addresses, phone numbers, browser-related details, purchase information, vehicle plates and IP addresses. The alleged records include bookings for airport services and SMS messages connected to reservations.

Attackers cite exposed credentials

The extortion group claimed it accessed MAG systems through administrative keys allegedly exposed in front-end JavaScript on airport websites. That assertion has not been confirmed by MAG or independently validated.

People who have used parking, lounge, Fast Track or Wi-Fi services at the affected airports may wish to remain alert for phishing emails, fraudulent calls and text messages that reference travel or booking information. Reusing passwords across services can also increase risk if account-related details were included in the exposed material.

MAG has said its airport operations remain unaffected. The incident highlights the security and privacy risks associated with customer data held across third-party platforms and online booking systems.