Thursday, September 3, 2026

UK airport hackers leak stolen customer data

FulcrumSec, the threat actor that earlier laid claim to the late-August breach of IT systems owned by Manchester Airports Group (MAG), has made public half a terabyte of data on 8.7 million people who transited through East Midlands, Manchester, and Stansted airports, apparently after its extortion attempts were rebuffed.

First reported on 27 August, the breach affected data related to bookings for parking facilities, airport lounges, Fast Track services and Wi-Fi network logins. The dataset, which has been reviewed by HaveIBeenPwned, comprises details on user browsers, IP addresses, geolocation, email addresses and phone numbers, purchase histories, vehicle registration plates, and names. However, per MAG’s earlier statements, financial data is not thought to have been affected.

In statements posted to FulcrumSec’s leak site, relayed via social media platform X, the gang said: “Today we are releasing the Manchester Airports Group dataset: every customer, event, configuration that serves Manchester Airport, Lonon Stansted and East Midlands Airport. Half a terabyte, and every byte of it is pure PII [Personally Identifiable Information].”

The gang went on to claim that it had decided not to release “the most dangerous part” of the breached dataset, which it said related to the upcoming travel schedules of about 200,000 individuals. FulcrumSec’s spokesperson said this could create an “ideal opportunity for burglars, stalkers and worse”.

It also exposed the vehicle registration numbers of at least three individuals working in the UK judicial system, who have supposedly booked parking at MAG sites in the coming weeks, and said it is in possession of data on high-profile individuals including celebrities, journalists, MPs, sporting figures, and over 11,000 NHS workers.

FulcrumSec made a series of further claims, including that it had gained access to MAG’s systems using iterable admin keys contained in the frontend JavaScript code of its public-facing websites.

The cyber criminals went on to lambast their victim, accusing MAG of “negligence” and “lack of concern” for travellers. The gang said the organisation had lied about the scope of the breach.

The veracity of FulcrumSec’s claims has not been established and no public statement has been made as to their accuracy. Computer Weekly reached out to the airport group but had not received a response at the time of publication.

Timon Johnson, principal cyber essentials assessor at Closed Door Security, said: “This is an expected update, but it’s one none of the victims wanted to hear. It was always unlikely MAG would pay the ransom demand as it is akin to doing business with criminals, [but] it’s also highly unlikely the data would ever have been returned in full without further exploitation.

“Now that the data is available for free on the dark web, other criminals will be working to exploit it,” said Johnson. “This is something the world witnessed earlier this year when threat actors started launching sextortion scams via data stolen from ShinyHunters in previous attacks that was also leaked on the dark web.”

Johnson said that people who have travelled through MAG airports should not assume their data would be ignored, and reiterated advice to be vigilant for scams via email, phone call, or SMS. Consumer guidance on cyber security for individuals and families is available from the UK’s National Cyber Security Centre (NCSC).

Who are FulcrumSec?

A relatively recent addition to the cyber criminal underground, FulcrumSec is a financially-motivated extortion gang that has also gone by the name The Threat Thespians.

According to NCC Group data, the gang was responsible for 23 recorded attacks in May of 2026 – other known victims include pharma giant Novo Nordisk, engineering firm Arup Group, and data analytics specialist LexisNexis.

According to Sysdig’s Crystal Morin, FulcrumSec targets largely cloud-native businesses and breaches their environments by exploiting either hardcoded credentials – as may have been the case with MAG – unpatched applications, or misconfigured storage buckets.

“Once they’re able to breach a victim’s environment, the group leverages the data for extortion. If their demands are not met, FulcrumSec then sells whatever data they’ve stolen. It’s important to note, too, that there is no encryption or disruption involved in a FulcrumSec breach. They call their extortion model ‘steal and squeeze’,” wrote Morin.

Muhammad Yahya Patel, virtual chief information security officer (vCISO) and cyber security advisor for EMEA at Huntress, said that in releasing the stolen data for free, FulcrumSec was deliberately seeking to maximise the harm, and reputational damage, that MAG experiences as a warning to others.

“Publishing almost nine million records for free isn’t just punishment for MAG it’s a marketing campaign aimed at every other organisation watching. Pay up, or your customers’ data gets handed to every fraudster and scammer on the internet at no cost,” said Patel.

“Refusing to pay a ransom is the right call. But nearly nine million people are now paying a different price for a decision that was never theirs to make.”

Related Articles

Latest Articles