FulcrumSec ransomware steals 86GB from Manchester Airports Group
A ransomware gang called FulcrumSec claims to have stolen 86GB of data from Manchester Airports Group by finding exposed login keys in their website code. The attackers say they have booking details, payment info, and personal records of millions of travelers.
- Report priority
- High
- Victim
- Manchester Airports Group
- Group
- FulcrumSec
What is known
The attackers found exposed login keys hidden in the airports' website code, which let them access internal systems and steal data.
What to do
Check if you booked airport services like Fast Track passes, used airport lounges, or registered for WiFi at Manchester, London Stansted, or East Midlands airports between now and August 27, 2024.
Monitor your accounts for unusual activity and consider freezing credit if you see signs of fraud. The airports are notifying affected customers directly with next steps.
Reported details
The attackers searched the airports' website code and found hidden login keys. They used those keys to break into the airport's internal systems. Inside, they copied 86GB of customer data, including travel plans, payment details, and personal info. They then demanded a ransom to return the data.
The extortion group FulcrumSec claims to have stolen approximately 86GB of data from Manchester Airports Group (MAG) by exploiting exposed API credentials found in client-side JavaScript. These credentials were embedded in code running in users' browsers, meaning they could be accessed via standard browser developer tools. The stolen data allegedly includes personal identifiers, historical booking details, marketing information, and sensitive travel records, such as Fast Track bookings, arrival times, terminal information, and payment amounts, linked to nearly 200,000 upcoming travel plans for 2026.
MAG initially disclosed a breach affecting 8.7 million customers, primarily exposing email addresses, phone numbers, vehicle registrations, and postcodes, but FulcrumSec's claims suggest a far broader and more detailed dataset was compromised. The group intends to publish the stolen data and a technical account of the intrusion.
References
- bleepingcomputer.com · fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data SecurityAffairs
- infosec.exchange · @securityaffairs SecurityAffairs
- securityaffairs.co · wordpress SecurityAffairs
- bleepingcomputer.com · anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage BleepingComputer
- darkreading.com · android-malware-hijacks-update-system-car-head-units DarkReading
- sonatype.com · a-reported-log4j-rce-is-more-complicated-than-it-looks Sonatype
- guide.sonatype.com · 4dab11e9-1836-4dd0-b764-d5002fed0b20 Sonatype
- cyberkendra.com · log4j-bug-report-pulled-researcher.html Sonatype
- guide.sonatype.com · sonatype-2026-006746 Sonatype
- github.com · issue #4255 Sonatype
- stepsecurity.io · arrayref-rust-crate-supply-chain-attack StepSecurity
- sec.cloudapps.cisco.com · cisco-sa-notice-f2SiMFxl Cisco PSIRT
- cert.ssi.gouv.fr · CERTFR-2026-AVI-1060 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-1066 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-1069 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-1086 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-1093 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-1095 CERT-FR Advisories
- acn.gov.it · rilevata-vulnerabilita-in-prodotti-cpanel-1 ACN CSIRT Italy
- acn.gov.it · risolta-vulnerabilita-su-gitlab-ai-gateway ACN CSIRT Italy
- acn.gov.it · rilevate-vulnerabilita-in-prodotti-mongodb-3 ACN CSIRT Italy
- acn.gov.it · sanata-vulnerabilita-in-grafana-alloy ACN CSIRT Italy
- acn.gov.it · risolta-vulnerabilita-in-siemens-element-maps ACN CSIRT Italy
- acn.gov.it · aggiornamenti-di-sicurezza-sanano-molteplici-vulnerabilita-in-servicenow ACN CSIRT Italy
- acn.gov.it · ee-21 ACN CSIRT Italy
- acn.gov.it · risolte-vulnerabilita-in-prodotti-nvidia-2 ACN CSIRT Italy
- acn.gov.it · aggiornamenti-per-prodotti-autodesk-12 ACN CSIRT Italy
- acn.gov.it · vulnerabilita-in-prodotto-rapid7 ACN CSIRT Italy
- acn.gov.it · rilevate-vulnerabilita-in-gitlab ACN CSIRT Italy
- acn.gov.it · risolta-vulnerabilita-su-zimbra-collaboration-2 ACN CSIRT Italy
- advisory.splunk.com · SVD-2026-0808 Splunk
- advisory.splunk.com · SVD-2026-0807 Splunk
- advisory.splunk.com · SVD-2026-0806 Splunk
- advisory.splunk.com · SVD-2026-0804 Splunk
- advisory.splunk.com · SVD-2026-0801 Splunk
- discuss.hashicorp.com · 77657 HashiCorp
- hashicorp.com · subprocessors HashiCorp
- ibm.com · index.html HashiCorp
- cisecurity.org · multiple-vulnerabilities-in-oracle-products-could-allow-for-arbitrary-code-execution_2026-084 MS-ISAC
- bleepingcomputer.com · chrome-web-store-extensions-caught-stealing-crypto-browser-data BleepingComputer