FulcrumSec has claimed responsibility for the Manchester Airports data breach, alleging that it stole around 86GB of customer, booking and travel information.
Hackers claim theft of 86GB of data
Manchester Airports Group, or MAG, disclosed the incident on August 27. The company said attackers stole customer data connected to Manchester, London Stansted and East Midlands airports.
MAG initially said the affected information related to airport Wi-Fi registrations and car park, lounge and Fast Track bookings.
FulcrumSec later claimed it carried out the attack and supplied samples of allegedly stolen records. The group says it accessed a much broader set of data than MAG initially described.
Samples show detailed booking information
BleepingComputer reviewed samples and verified one record against a traveller’s known Manchester Airport purchase history.
The data reportedly included Fast Track purchases, booking references, arrival times, terminal details, amounts paid and historical spending.
The samples also contained a roughly 21.5GB Manchester customer export. It allegedly combined customer identifiers, past booking activity and marketing classifications.
FulcrumSec claims the full Manchester Airports data breach involved nearly 200,000 records connected to upcoming travel during the rest of 2026. However, the group’s claimed access, data volume and number of records remain unverified.
Exposed data could support targeted scams
The reviewed records reportedly included email addresses, phone numbers, vehicle registrations and postcodes. They also contained booking references, airport and product selections, prices, discounts, parking dates, IP addresses, device information and approximate locations.
BleepingComputer said it did not find payment-card or bank-account information in the reviewed material.
However, the combination of travel, vehicle and booking data could help criminals create convincing phishing emails, text messages and phone scams. Attackers could impersonate MAG or a booking provider and refer to real travel details to gain trust.
MAG said it has contacted affected customers, including people with upcoming bookings.
MAG declines to address specific claims
FulcrumSec said it gained access through airport-specific Iterable API credentials exposed in client-side JavaScript. MAG declined to address the group’s specific claims.
The airport operator said it has taken effective steps to protect customers. It also repeated that it will never contact people unexpectedly to request payment-card details, bank information or passwords.
MAG said the incident has not disrupted airport operations. Passenger safety and aviation security were not affected.
A MAG spokesperson previously indicated that around 8.7 million customers may be affected, although most reportedly had only their email address exposed. If confirmed, the Manchester Airports data breach would rank as the largest known customer breach involving a British airport operator.


0 responses to “FulcrumSec Claims Manchester Airports Hack Stole 86GB of Data”