Extortion Group FulcrumSec Claims 86 GB of Manchester Airports Group Data Stolen via Exposed API Credentials
What Happened – FulcrumSec announced it exfiltrated roughly 86 GB of data from Manchester Airports Group (MAG) after discovering airport‑specific Iterable API credentials embedded in client‑side JavaScript. The group released sample records showing personal identifiers, booking histories and payment details for millions of travelers.
Why It Matters for Trust & Control Assurance
- This incident illustrates a classic control‑objective failure: inadequate protection of API secrets and weak access‑control policies for external‑facing services.
- Continuous control‑assurance programs that inventory, monitor, and rotate secrets can detect such misconfigurations before they become exploitable.
- Evidence of robust credential‑management processes (e.g., secret‑scanning, key rotation, least‑privilege API scopes) provides defensible audit trails for regulators and partners.
Who Is Affected – Aviation & transportation operators, airport‑service vendors, and the 8.7 million passengers whose contact and travel details were exposed.
Recommended Actions
- Conduct an immediate inventory of all client‑side code for embedded secrets and remove any credentials.
- Implement automated secret‑scanning in CI/CD pipelines and enforce “never expose secrets in front‑end code” policies.
- Rotate compromised API keys, restrict scopes to the minimum required, and enable anomaly‑based monitoring for API usage.
- Update incident‑response playbooks to include credential‑exposure scenarios and notify affected travelers per regulatory requirements.
Source: Security Affairs
Technical Notes – Attack vector: misconfiguration – API credentials hard‑coded in JavaScript delivered to browsers. Data types: email addresses, phone numbers, vehicle registrations, postcodes, and detailed flight‑booking records (dates, times, payment amounts). No ransomware or malware reported. Source: same as above