UK airport hackers leak stolen buyer information
FulcrumSec, the menace actor that earlier laid declare to the late-August breach of IT methods owned by Manchester Airports Group (MAG), has made public half a terabyte of knowledge on 8.7 million individuals who transited by East Midlands, Manchester, and Stansted airports, apparently after its extortion makes an attempt had been rebuffed.
First reported on 27 August, the breach affected information associated to bookings for parking amenities, airport lounges, Quick Observe providers and Wi-Fi community logins. The dataset, which has been reviewed by HaveIBeenPwned, includes particulars on person browsers, IP addresses, geolocation, e mail addresses and cellphone numbers, buy histories, car registration plates, and names. Nevertheless, per MAG’s earlier statements, monetary information just isn’t thought to have been affected.
In statements posted to FulcrumSec’s leak web site, relayed through social media platform X, the gang stated: “In the present day we’re releasing the Manchester Airports Group dataset: each buyer, occasion, configuration that serves Manchester Airport, Lonon Stansted and East Midlands Airport. Half a terabyte, and each byte of it’s pure PII [Personally Identifiable Information].”
The gang went on to assert that it had determined to not launch “essentially the most harmful half” of the breached dataset, which it stated associated to the upcoming journey schedules of about 200,000 people. FulcrumSec’s spokesperson stated this might create an “splendid alternative for burglars, stalkers and worse”.
It additionally uncovered the car registration numbers of at the least three people working within the UK judicial system, who’ve supposedly booked parking at MAG websites within the coming weeks, and stated it’s in possession of knowledge on high-profile people together with celebrities, journalists, MPs, sporting figures, and over 11,000 NHS staff.
FulcrumSec made a collection of additional claims, together with that it had gained entry to MAG’s methods utilizing iterable admin keys contained within the frontend JavaScript code of its public-facing web sites.
The cyber criminals went on to lambast their sufferer, accusing MAG of “negligence” and “lack of concern” for travellers. The gang stated the organisation had lied in regards to the scope of the breach.
The veracity of FulcrumSec’s claims has not been established and no public assertion has been made as to their accuracy. Laptop Weekly reached out to the airport group however had not acquired a response on the time of publication.
Timon Johnson, principal cyber necessities assessor at Closed Door Safety, stated: “That is an anticipated replace, nevertheless it’s one not one of the victims wished to listen to. It was all the time unlikely MAG would pay the ransom demand as it’s akin to doing enterprise with criminals, [but] it’s additionally extremely unlikely the info would ever have been returned in full with out additional exploitation.
“Now that the info is on the market without spending a dime on the darkish internet, different criminals might be working to use it,” stated Johnson. “That is one thing the world witnessed earlier this 12 months when menace actors began launching sextortion scams through information stolen from ShinyHunters in earlier assaults that was additionally leaked on the darkish internet.”
Johnson stated that individuals who have travelled by MAG airports mustn’t assume their information can be ignored, and reiterated recommendation to be vigilant for scams through e mail, cellphone name, or SMS. Shopper steerage on cyber safety for people and households is on the market from the UK’s Nationwide Cyber Safety Centre (NCSC).
Who’re FulcrumSec?
A comparatively current addition to the cyber prison underground, FulcrumSec is a financially-motivated extortion gang that has additionally passed by the identify The Risk Thespians.
Based on NCC Group information, the gang was answerable for 23 recorded assaults in Could of 2026 – different recognized victims embrace pharma large Novo Nordisk, engineering agency Arup Group, and information analytics specialist LexisNexis.
Based on Sysdig’s Crystal Morin, FulcrumSec targets largely cloud-native companies and breaches their environments by exploiting both hardcoded credentials – as could have been the case with MAG – unpatched functions, or misconfigured storage buckets.
“As soon as they’re capable of breach a sufferer’s atmosphere, the group leverages the info for extortion. If their calls for should not met, FulcrumSec then sells no matter information they’ve stolen. It’s vital to notice, too, that there isn’t any encryption or disruption concerned in a FulcrumSec breach. They name their extortion mannequin ‘steal and squeeze’,” wrote Morin.
Muhammad Yahya Patel, digital chief data safety officer (vCISO) and cyber safety advisor for EMEA at Huntress, stated that in releasing the stolen information without spending a dime, FulcrumSec was intentionally looking for to maximise the hurt, and reputational harm, that MAG experiences as a warning to others.
“Publishing nearly 9 million information without spending a dime is not simply punishment for MAG it is a advertising marketing campaign aimed toward each different organisation watching. Pay up, or your prospects’ information will get handed to each fraudster and scammer on the web without charge,” stated Patel.
“Refusing to pay a ransom is the precise name. However practically 9 million individuals at the moment are paying a unique value for a choice that was by no means theirs to make.”

