Contained High impact Data breach Checked 3d ago

Manchester Airports Group breach exposes 8.7 million customers

Hackers stole data linked to about 8.7 million customers of Manchester, London Stansted and East Midlands airports. Most affected records contained email addresses, while other stolen data included contact, postcode, vehicle and booking details. FulcrumSec posted download links on September 1 and, according to reporting on September 2, appears to have released nearly all of the roughly 549 GB of data it says it took. On September 7, security researcher Scott Helme independently confirmed that three airport-specific API keys had been exposed in public website code for more than four years. He found the keys removed and disabled, blocking that access route. MAG has contacted affected customers and said airport operations and passenger safety were unaffected.

Started
Aug 27, 2026
Latest activity
Sep 7, 2026
Attributed to
FulcrumSecConfirmed
Where
United Kingdom
Sectors
Transport
Scale
Manchester Airports Group and its three UK airports

Current status

On September 7, security researcher Scott Helme found all three exposed API keys removed and disabled, blocking that access route.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Who is behind it

FulcrumSec claims responsibility, but MAG has not publicly confirmed the group's identity.

Impact

Customer email addresses, phone numbers, postcodes or home addresses, vehicle registrations, purchase history and booking information were stolen. FulcrumSec posted download links on September 1 and, as of September 2 and 3, appears to have published nearly all of the data it claims to hold, describing it as personal information. The group gave the data away for free rather than selling it at first, which security experts called an unusual move, and by September 4 was also reported to be offering the database for sale on the dark web.

What to do

People contacted by MAG should watch for convincing emails, texts or calls about airport bookings and never give payment details or passwords to an unexpected caller. Anyone who believes their data was exposed can contact the Information Commissioner's Office for guidance on their rights.

Timeline

  1. Sep 7, 2026

    Security researcher Scott Helme found that three airport-specific API keys had been exposed in public website code since mid-2022 and were now removed and disabled, blocking access through them.

    Containedscotthelme.co.uk
  2. Sep 5, 2026

    The Mail on Sunday published its own analysis of the leaked files, reporting entries tied to a circuit judge, parliamentary staff, Home Office and Bank of England employees, and armed forces members, plus emails appearing to belong to celebrities and footballers. It also reported MAG has said the intrusion itself took place on August 22 and 23, before being confirmed publicly on August 27.

    Activedailymail.com
  3. Sep 4, 2026

    Security reporters said FulcrumSec has listed the stolen Manchester Airports Group database for sale on the dark web, in addition to the data it already released for free, and cyber experts noted MAG's refusal to pay follows standard guidance not to reward extortion.

    Activetechradar.com
  4. Sep 3, 2026

    MAG said it has contacted all customers affected by the breach, including those with upcoming bookings, and is working with authorities and security experts. It said it believes it has taken effective measures to protect customers and that passenger safety and airport operations remain unaffected.

    Activesilicon.co.uk
  5. Sep 2, 2026

    Computer Weekly reported the leaked dataset had been reviewed by Have I Been Pwned, and that FulcrumSec claims it got in using exposed Iterable admin API keys left in MAG's public website code rather than by directly hacking in. The group also claimed, without independent confirmation, that the data includes records tied to some UK judicial staff, celebrities, journalists, MPs and more than 11,000 NHS workers.

    Activecomputerweekly.com
  6. Sep 2, 2026

    Infosecurity Magazine reported that FulcrumSec appears to have leaked almost all of the roughly 549 GB of uncompressed data it claims to have stolen from MAG, describing the data as personal information.

    Activeinfosecurity-magazine.com
  7. Sep 1, 2026

    FulcrumSec posted download links on its leak site and claimed it had released most of the stolen MAG data. It said it withheld records covering future travel plans.

    Activefulcrumsec.vg
  8. Aug 30, 2026

    FulcrumSec claimed the attack, supplied partly validated samples and threatened to publish the stolen data.

    Activebleepingcomputer.com
  9. Aug 27, 2026

    MAG told The Register that about 8.7 million customers were affected and that it had not paid the extortion demand.

    theregister.com
  10. Aug 27, 2026

    MAG confirmed the data theft, said it had contained the risk and reported no disruption to airport operations.

    Containedmanchesterairport.co.uk

Sources

Related reports