Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer
FulcrumSec says it found live API credentials sitting in client-side JavaScript. MAG disclosed 8.7 million affected customers, most with only an email address exposed.
Manchester Airports Group, the operator behind Manchester, London Stansted and East Midlands airports, disclosed on August 27 that an unauthorized third party had stolen customer data. The company's own description pointed to car park, lounge and Fast Track bookings, plus in-airport Wi-Fi registrations, as the source of the exposure.
The extortion group behind it, which calls itself FulcrumSec, told BleepingComputer it stole roughly 86 gigabytes. Samples the outlet reviewed were consistent with MAG's disclosure, but also suggested the breach reached deeper into customer, booking and travel detail than the initial statement let on. That gap, between what a company says publicly and what a reporter finds sitting in a leaked sample, is not unusual in these disclosures, but it is still worth flagging every time it happens.
The technical root of the intrusion is almost mundane, which is what makes it worth writing about. FulcrumSec says it found airport-specific Iterable API credentials embedded directly in client-side JavaScript, code that runs inside every visitor's browser. Anyone who opened developer tools on the site could, in theory, have read those credentials straight off the page. Iterable is a marketing and customer-engagement platform; API keys for services like that have no business shipping inside code the public can inspect.
The company's own description pointed to car park, lounge and Fast Track bookings, plus in-airport Wi-Fi registrations, as the source of the exposure.
MAG says 8.7 million customers were affected in total, though the company maintains that most of them had nothing more than an email address exposed. The attackers reportedly demanded a ransom, which the company is understood to have refused. A MAG spokesperson declined to address FulcrumSec's specific claims when asked, pointing instead to an updated statement confirming that customers with upcoming bookings had been contacted directly.
Client-side credential leaks keep recurring across sectors precisely because they are invisible in normal code review unless someone specifically goes looking in the browser, not the server.
Airports and airlines have had a rough run of it this year. Several major carriers and at least two other European airport groups disclosed customer data incidents in 2026 alone, and the sector's appeal to extortion crews is not mysterious: a single traveler's booking record links a name, a travel date, a home address and often a payment trail, which is a denser bundle of resellable personal data than most retail transactions produce. MAG's Fast Track and lounge booking systems, built for convenience rather than for handling the kind of sensitive linkage a full itinerary represents, were never designed with that threat model in mind.
Based on reporting by BleepingComputer.




