Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

FulcrumSec Claims Theft of 86 GB Customer Data from Manchester Airports Group

FulcrumSec says it stole ~86 GB of passenger, booking and Wi‑Fi data from Manchester Airports Group after exploiting API credentials exposed in client‑side JavaScript. The incident underscores the importance of continuous credential‑management controls for audit readiness.

LiveThreat™ Intelligence · 📅 August 30, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
2 recommended
📰
Source
bleepingcomputer.com

FulcrumSec Claims Theft of 86 GB Customer Data from Manchester Airports Group

What Happened – The extortion group FulcrumSec announced that it exfiltrated roughly 86 GB of data from Manchester Airports Group (MAG), the UK’s largest airport operator. The stolen material includes detailed car‑park, lounge, Fast‑Track and Wi‑Fi registration records, as well as an estimated 21.5 GB export of consolidated passenger profiles and up to 200,000 up‑coming‑travel records.

Why It Matters for Trust & Control Assurance

  • The breach stems from exposed API credentials in client‑side JavaScript, a classic access‑control failure that a continuous control‑assurance program should detect, log and remediate.
  • Demonstrates the need for real‑time credential‑management monitoring and evidence‑backed audit trails—the exact control area Verisq’s ACCESS_CONTROLS capability helps you prove.
  • Highlights how a single weak point can jeopardize multiple regulatory expectations (e.g., GDPR, NIST CSF 2.0) across the same control objective.

Who Is Affected – Aviation & transportation operators, travel‑service platforms, and any third‑party SaaS that integrates with airport‑specific APIs.

Recommended Actions

  • Inventory all client‑side JavaScript that contains API keys or secrets; rotate any exposed credentials immediately.
  • Map the “credential‑management” control to your audit‑readiness framework and collect continuous evidence (e.g., secret‑scan logs, privileged‑access reviews).
  • Conduct a focused penetration test on public‑facing APIs to verify that least‑privilege and token‑expiry policies are enforced.

Source: BleepingComputer

Technical Notes – The attackers leveraged Iterable API credentials that were inadvertently exposed in JavaScript bundles. No specific CVE is cited; the vector is a misconfiguration / credential exposure. Data types include personally identifiable information (names, travel itineraries, payment references) and marketing classifications.

📰 Original Source
https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →