FulcrumSec has published data allegedly stolen from Manchester Airports Group after the UK airport operator confirmed a cyberattack affecting approximately 8.7 million customers across Manchester Airport, London Stansted and East Midlands Airport.
The extortion group claims the newly released archives contain 8,672,291 customer profiles, more than 1.16 billion activity records, 2.48 million purchase events, 108,077 unique vehicle registrations and hundreds of thousands of rendered SMS messages.
FulcrumSec also claims the stolen dataset contains 190,849 bookings dated Sept. 1, 2026 or later, creating an unusually sensitive exposure because some records allegedly connect identifiable customers and vehicles with future airport parking and travel dates.
The group says it withheld the upcoming travel records from its public release because of the physical-security risks they could create.
MAG confirmed data theft affecting 8.7 million customers
Manchester Airports Group disclosed the incident on Aug. 27, confirming that an unauthorized third party obtained customer information associated with car park, lounge and Fast Track bookings and in-airport Wi-Fi registrations.
MAG said the compromised information includes email addresses, phone numbers, vehicle registrations and postcodes. The company said neither it nor the affected system holds customers’ bank or payment details.
“At no point has passenger safety or aviation security been compromised,” MAG said in its incident statement.
The company said airport operations remained unaffected and that it restricted access to affected systems, engaged cybersecurity specialists and notified relevant authorities.
MAG also temporarily suspended access to its online Manage My Booking service as a precaution while responding to the incident.
FulcrumSec publishes airport datasets
FulcrumSec now claims to have released 4 compressed archives containing data associated with Manchester Airport, London Stansted, East Midlands Airport and a consolidated customer database.
The group lists the compressed archives at approximately 74.6 GB in total and claims the extracted data expands to roughly 550 GB.
According to FulcrumSec, the customer archive contains 8,672,291 profiles, including approximately 4.39 million associated with Manchester, 3.53 million with Stansted and 755,061 with East Midlands.
The group claims the broader dataset contains:
- 8,672,291 customer profiles
- 1,169,302,811 activity events
- 2,482,763 purchase events
- 461,433 rendered SMS messages
- 108,077 unique vehicle registration plates
- 190,849 bookings dated Sept. 1, 2026 or later
- Marketing campaigns, customer journeys, lists, segments and templates
FulcrumSec says profile information includes names, email addresses, mobile numbers, location information and IP addresses. Purchase and booking records allegedly contain information associated with airport parking, lounges and Fast Track products.
BreachNews is not linking to or distributing the stolen archives.
Future bookings create physical-security concern
The most concerning element of FulcrumSec’s latest disclosure involves future airport bookings.
The group claims 190,849 records contain travel dates beginning Sept. 1 or later, including 106,814 associated with Manchester, 71,108 with Stansted and 12,927 with East Midlands.
FulcrumSec further claims 142,755 of those records connect a vehicle registration with the purchaser’s email address and dated booking information.
If authentic, that combination could create risks extending beyond conventional phishing and identity-based fraud. Information linking a person, vehicle and future airport parking period could potentially reveal when an individual is expected to be away from home.
FulcrumSec claims it removed the future travel details from the publicly distributed archives because of those risks. BreachNews has not independently verified that all such records were removed.
Group claims exposed Iterable keys enabled access
FulcrumSec claims it gained access through credentials associated with Iterable, a customer communications and marketing platform.
According to the group, separate administrative credentials were exposed in client-side JavaScript used by the websites for Manchester Airport, Stansted Airport and East Midlands Airport. FulcrumSec claims those credentials provided access to customer and marketing data associated with each airport.
The group alleges the same configuration problem existed across all 3 airport websites.
MAG has not publicly confirmed FulcrumSec’s account of the initial access method. Its public incident statement does not identify Iterable or explain how the unauthorized third party obtained access.
Published data goes beyond MAG’s initial disclosure
MAG’s confirmed disclosure identified email addresses, phone numbers, vehicle registrations and postcodes among the information accessed. FulcrumSec’s publication claims a considerably broader collection that includes purchase histories, marketing activity, SMS content, booking information and detailed customer engagement records.
The 1.16 billion activity records claimed by FulcrumSec should not be interpreted as 1.16 billion affected people. The group says the records primarily represent events associated with the approximately 8.67 million customer profiles, including email sends, opens, clicks, subscriptions, bounces and other marketing activity.
FulcrumSec also claims the dataset contains addresses associated with government, judicial, military, healthcare, emergency-services and defence-sector organizations. BreachNews is not publishing the identities, travel schedules, vehicle registrations or other sensitive details of individuals contained in the samples.
MAG has confirmed that customer information was stolen but had not publicly confirmed FulcrumSec’s newly claimed data volumes, the alleged Iterable credential exposure or the contents of the Sept. 1 data release at time of publication.











