Hackers have published data they claim to have stolen from Manchester Airports Group, exposing information linked to nearly 8.7 million customers across Manchester, London Stansted and East Midlands airports.
The Manchester Airports data breach did not involve bank or payment details, according to the airport operator. However, the exposed information includes email addresses, phone numbers, postcodes, vehicle registrations and future booking data.
Attackers claim they released 8.7 million records
The extortion group FulcrumSec claimed it had published the full Manchester Airports data breach after the company refused to pay a ransom.
The group said its alleged database contains 8,672,291 customer profiles, more than 1.1 billion marketing events and almost 2.5 million purchases. It also claimed to hold SMS messages, vehicle-registration data, future booking information and platform configuration details.
MAG disclosed the cyberattack on August 27. The company said the affected systems held data collected through Wi-Fi registrations, car park bookings, lounge services and Fast Track reservations.
MAG said airport operations and passenger safety were not affected.
Personal data could create physical security risks
The group claimed that some records belong to public figures, politicians and military personnel. If authentic, the combination of contact details, postcodes and vehicle registrations could create risks beyond online fraud.
Criminals could use the information in phishing campaigns, impersonation attempts, stalking or other targeted scams. Even customers whose email address was the only exposed detail may face a higher risk of convincing phishing messages.
MAG said the vast majority of affected customers had email addresses exposed. That still makes the incident one of the largest reported airport-related data breaches in the UK.
FulcrumSec claims website keys enabled access
FulcrumSec alleged that it found exposed keys on MAG’s main website and used them to obtain access. The group claimed the keys were visible to visitors through standard browser inspection tools.
Those claims have not been independently verified. MAG has confirmed that an unauthorised third party obtained customer data but has not publicly confirmed the attackers’ account of how the breach happened.
The group said MAG refused its ransom demand before it released the data. It also claimed to have removed some of the most sensitive material before publication.
Customers should watch for targeted scams
People who used services at Manchester, London Stansted or East Midlands airports should remain alert for suspicious emails, calls and text messages.
Attackers can use known travel information to make fraudulent messages appear credible. Customers should avoid opening unexpected links, sharing account details or providing payment information in response to unsolicited contact.
The Manchester Airports data breach highlights the risks created when travel, contact and vehicle information appears together in a leaked dataset. Such records can give criminals enough context to target victims long after the initial attack.


0 responses to “Hackers Publish Data From Nearly 9 Million UK Airport Travellers”