Extortion Group Claims Manchester Airports Group Data Breach
The FulcrumSec extortion group claims responsibility for a data breach at Manchester Airports Group (MAG), a major UK airport operator. The attackers stole approximately 86 gigabytes of customer data, including booking information, and have demanded a ransom, though MAG has not disclosed further details about the threat actor or the ransom amount. Operations at the airports remain unaffected, and no passenger safety was compromised.
Manchester Airports Group (MAG), a leading UK airport operator, recently disclosed a data breach impacting approximately 8.7 million customers. The breach involved the theft of data related to car park, lounge, and Fast Track bookings, as well as in-airport Wi-Fi sign-ups across Manchester, London Stansted, and East Midlands airports. MAG stated that it immediately contained the risk and is working with specialist advisors to protect its systems and customers. The compromised data included email addresses, phone numbers, vehicle registrations, and postcodes.
MAG confirmed that the data was sourced from a database hosted by a third party and that the group received a ransom demand from the attackers. However, they declined to share further details about the threat actor and the specific ransom amount.
The FulcrumSec extortion group publicly claimed responsibility for the incident and the theft of approximately 86 gigabytes of data. FulcrumSec emerged in 2025 and has been linked to previous high-profile hacks, including incidents at Novo Nordisk and LexisNexis.
Related reports indicate a similar campaign targeting PTC Windchill, attributed to the Cl0p ransomware group, and a separate data breach impacting CareCloud, affecting at least 3.7 million individuals, and another impacting Heights Finance, affecting at least 1.2 million individuals.