The Manchester Airports Group data breach has been claimed by extortion group FulcrumSec, which told BleepingComputer it took approximately 86 GB of data, and samples reviewed by the outlet suggest the exposed information goes considerably further than MAG’s own disclosure acknowledged.
How the Manchester Airports Group Data Breach Unfolded
According to TechTimes, Manchester Airports Group detected the unauthorised access on 25 August 2026 and went public two days later on 27 August, a 48-hour disclosure window. In that statement, MAG, the United Kingdom’s largest airport operator, said an unauthorised third party had stolen customer data tied to Manchester, London Stansted, and East Midlands airports, with affected information drawn from car park, lounge, and Fast Track bookings as well as in-airport Wi-Fi registrations.
FulcrumSec contacted BleepingComputer directly, claiming responsibility and sharing data samples as evidence. BleepingComputer validated at least one record by cross-referencing it with a traveller’s known Manchester Airport purchase history. That record accurately listed previous Fast Track purchases, booking and scheduled-arrival times, the terminal used, amounts paid, purchase references, total spending, and the apparent purpose of the trips, detail well beyond what MAG’s public statement described.
The group claims it obtained access using airport-specific Iterable API credentials exposed in client-side JavaScript. Among the material allegedly taken was a roughly 21.5 GB Manchester customer export containing consolidated profiles that combined customer identifiers with historical booking activity and marketing classifications.
Nearly 200,000 Future-Travel Records Allegedly Among the Manchester Airports Group Data Breach Haul
The picture gets more uncomfortable from there. FulcrumSec says the stolen material includes nearly 200,000 records related to upcoming travel during the remainder of 2026, containing dates, times and booking information linked to personally identifiable information. The group told BleepingComputer it is considering withholding or redacting those records because of the potential for what it described as “real-world harm.”
BleepingComputer was careful to note it could not independently verify the alleged source or full extent of the access, the total dataset size, or the claim about the upcoming-travel records. After completing its verification work, the outlet securely deleted all supplied material without retaining copies.
Beyond the email addresses, phone numbers, vehicle registrations and postcodes that MAG disclosed, the sampled records also contained purchase and booking references, airport and product selections, prices, discounts, booking status, parking dates and times, historical spending, IP addresses, approximate locations, device information and customer-engagement data. BleepingComputer did not observe payment-card or bank-account information in the reviewed material.
The postcode exposure deserves particular attention. Unlike US ZIP codes, which generally cover broader delivery areas, a full UK postcode can identify a small cluster of neighbouring properties. The UK Office for National Statistics puts a typical small-user postcode at approximately 15 addresses, with some assigned to a single address. Combined with contact details, vehicle information and travel data, that level of specificity opens the door to highly convincing phishing emails, text messages or telephone scams impersonating MAG or a booking provider.
MAG’s Response and the Scale of the Incident
When BleepingComputer asked MAG to address FulcrumSec’s specific claims (the 86 GB figure, the exposed credentials, the future-travel data) a spokesperson declined, pointing instead to an updated statement. “MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support,” the spokesperson said.
MAG has previously told the Manchester Evening News that around 8.7 million customers were affected, though only email addresses were exposed for the “vast majority” of them. That scale makes this the largest known customer data breach affecting a British airport operator. TechTimes reported that MAG generates annual revenue of approximately £1.5 billion, context that underscores the operational weight behind an organisation now managing both a major data incident and its customer communications simultaneously.
FulcrumSec is a financially motivated data-extortion group active since 2025. Rather than encrypting victims’ systems, it focuses on stealing sensitive corporate data and threatening publication. The group has previously claimed attacks on organisations including LexisNexis, Novo Nordisk, Global Schools Group, and Avnet. It says it intends to publish the stolen MAG data alongside a technical account of the intrusion.
MAG stressed that the incident has not caused operational disruption and that passenger safety and aviation security were not compromised. The company has advised affected customers to remain vigilant for suspicious emails, texts and calls, and confirmed it would never contact customers unexpectedly to request payment-card details, banking information or passwords. All customers with upcoming bookings have been contacted directly.

