FulcrumSec Claims Theft of 86 GB Customer Data from Manchester Airports Group
What Happened – The extortion group FulcrumSec announced that it exfiltrated roughly 86 GB of data from Manchester Airports Group (MAG), the UK’s largest airport operator. The stolen material includes detailed car‑park, lounge, Fast‑Track and Wi‑Fi registration records, as well as an estimated 21.5 GB export of consolidated passenger profiles and up to 200,000 up‑coming‑travel records.
Why It Matters for Trust & Control Assurance
- The breach stems from exposed API credentials in client‑side JavaScript, a classic access‑control failure that a continuous control‑assurance program should detect, log and remediate.
- Demonstrates the need for real‑time credential‑management monitoring and evidence‑backed audit trails—the exact control area Verisq’s ACCESS_CONTROLS capability helps you prove.
- Highlights how a single weak point can jeopardize multiple regulatory expectations (e.g., GDPR, NIST CSF 2.0) across the same control objective.
Who Is Affected – Aviation & transportation operators, travel‑service platforms, and any third‑party SaaS that integrates with airport‑specific APIs.
Recommended Actions
- Inventory all client‑side JavaScript that contains API keys or secrets; rotate any exposed credentials immediately.
- Map the “credential‑management” control to your audit‑readiness framework and collect continuous evidence (e.g., secret‑scan logs, privileged‑access reviews).
- Conduct a focused penetration test on public‑facing APIs to verify that least‑privilege and token‑expiry policies are enforced.
Source: BleepingComputer
Technical Notes – The attackers leveraged Iterable API credentials that were inadvertently exposed in JavaScript bundles. No specific CVE is cited; the vector is a misconfiguration / credential exposure. Data types include personally identifiable information (names, travel itineraries, payment references) and marketing classifications.