Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-31 ยท updated: 2026-08-31 ยท tags: [incident, breach, extortion, cybercrime-group, transport] ยท confidence: low ยท severity: high ยท affected_sectors: [transport, aviation] ยท au_impact: false

FulcrumSec Claims Manchester Airports Hack, Theft of 86 GB of Data

Summary

In late August 2026 the extortion group FulcrumSec claimed responsibility for breaching Manchester Airports Group (MAG), the operator of Manchester, London Stansted and East Midlands airports, and for stealing approximately 86 GB of data. The group said the haul includes around 200,000 records of travellers with upcoming flights, along with credentials for the Iterable email-marketing platform that were recovered from client-side JavaScript. BleepingComputer reported the claim on 31 August 2026.

Details

MAG confirmed it was aware of the claim and that an investigation was under way. The exposure of Iterable API credentials embedded in client-side JavaScript is significant because it can allow an attacker to send phishing emails from a trusted brand or to access subscriber and campaign data held in the marketing platform. The roughly 200,000 upcoming-travel records are particularly sensitive: they combine personal details with future itineraries, creating a credible basis for targeted social-engineering attacks ahead of travel.

Status and assessment

At the time of writing the breach remains a single-source claim by the threat actor, so confidence in the specific figures is low until MAG or independent researchers verify them. FulcrumSec has a history of publishing stolen data to pressure victims into paying. For travellers, the practical risk is phishing that references upcoming flights; for organisations, the incident underscores the risk of embedding third-party service credentials in browser-side code. Australian travellers using these UK airports could fall within the affected record set, although no Australian-specific angle has been reported.