FulcrumSec ransomware steals 86GB from Manchester Airports Group

Published August 10, 2026

A ransomware gang called FulcrumSec claims to have stolen 86GB of data from Manchester Airports Group by finding exposed login keys in their website code. The attackers say they have booking details, payment info, and personal records of millions of travelers.

Report priority
High
Victim
Manchester Airports Group
Group
FulcrumSec

What is known

The attackers found exposed login keys hidden in the airports' website code, which let them access internal systems and steal data.

What to do

Check if you booked airport services like Fast Track passes, used airport lounges, or registered for WiFi at Manchester, London Stansted, or East Midlands airports between now and August 27, 2024.

Monitor your accounts for unusual activity and consider freezing credit if you see signs of fraud. The airports are notifying affected customers directly with next steps.

Reported details

The attackers searched the airports' website code and found hidden login keys. They used those keys to break into the airport's internal systems. Inside, they copied 86GB of customer data, including travel plans, payment details, and personal info. They then demanded a ransom to return the data.

The extortion group FulcrumSec claims to have stolen approximately 86GB of data from Manchester Airports Group (MAG) by exploiting exposed API credentials found in client-side JavaScript. These credentials were embedded in code running in users' browsers, meaning they could be accessed via standard browser developer tools. The stolen data allegedly includes personal identifiers, historical booking details, marketing information, and sensitive travel records, such as Fast Track bookings, arrival times, terminal information, and payment amounts, linked to nearly 200,000 upcoming travel plans for 2026.

MAG initially disclosed a breach affecting 8.7 million customers, primarily exposing email addresses, phone numbers, vehicle registrations, and postcodes, but FulcrumSec's claims suggest a far broader and more detailed dataset was compromised. The group intends to publish the stolen data and a technical account of the intrusion.

References