Circuit Wire — a daily news update from the Circuit.

The data-extortion group FulcrumSec claimed on August 30 that it stole about 86 gigabytes of data from Manchester Airports Group, the operator of Britain's Manchester, London Stansted, and East Midlands airports. The group told BleepingComputer it got in after finding airport-specific Iterable API credentials exposed in client-side JavaScript, code that runs in visitors' browsers. Manchester Airports Group, known as MAG, first disclosed the breach on August 27 and says it reached about 8.7 million customers, most of whom had only an email address exposed. The affected data came from car park, lounge, and Fast Track bookings and from in-airport Wi-Fi sign-ups.

FulcrumSec shared samples with reporters, who validated one traveler's record against a real purchase history. The record listed past Fast Track bookings, arrival times, the terminal used, and amounts paid. The exposed material reportedly goes beyond the email addresses, phone numbers, vehicle registrations, and postcodes MAG first described, and also includes booking references, parking dates, historical spending, IP addresses, and device details. Investigators found no payment card or bank data in the samples.

The group claims the haul includes nearly 200,000 records tied to trips booked for the rest of 2026, each linked to a named person. FulcrumSec said it plans to publish the data but may hold back the future-travel records because of the risk of real-world harm. Security Affairs noted that a full UK postcode can point to a handful of homes, or even one, which makes the mix of travel dates, vehicles, and bookings useful for convincing phishing. MAG declined to address the specific claims and said it had contacted affected customers, including everyone with an upcoming booking, and warned that it would never contact them unexpectedly to ask for card details or passwords.

FulcrumSec has operated since 2025, stealing corporate data and threatening to leak it rather than locking systems, and has claimed earlier attacks on LexisNexis and Novo Nordisk. The MAG breach is the largest known theft of customer data from a British airport operator. It also lands less than a year after a September 2025 ransomware attack on Collins Aerospace check-in software disrupted systems at Heathrow, Brussels, and Berlin. Both cases point to the exposure airports carry through outside booking, parking, and loyalty platforms rather than systems they run themselves. MAG said the incident caused no operational disruption and did not affect aviation security.

Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.

Spotted something we should cover? Send tips and feedback via circuit-magazine.com.