Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal
Manchester Airports Group (MAG) suffered a data breach, with 8.8 million people's email addresses and phone numbers exposed. The attack was carried out by the FulcrumSec extortion gang, who exploited exposed admin keys on MAG’s website. MAG declined to pay a ransom, and the group has now released 550GB of stolen data, including booking information and vehicle registration details. The incident highlights the ongoing risk of exploiting exposed credentials and the potential consequences of not paying ransom demands.
Manchester Airports Group (MAG) experienced a significant data breach, resulting in the exposure of personal information for 8.8 million individuals. The incident was attributed to the FulcrumSec extortion gang, who gained access to MAG’s systems by leveraging exposed administrative keys found within the frontend JavaScript of the airport websites.
MAG disclosed the breach last week, noting that the attackers had stolen car park, lounge, and Fast Track booking data, along with in-airport Wi-Fi sign-ups at the Manchester, London Stansted, and East Midlands airports. The stolen data included email addresses, phone numbers, vehicle registrations, and postcodes.
FulcrumSec claims the stolen data includes 2,482,763 purchases (bookings for parking, lounge, and fast-track products), 461,433 SMS messages associated with bookings, car park, and vehicle registration, and 108,077 unique UK vehicle registration plates. The group also claims to have exfiltrated MAG platform’s configuration.
MAG confirmed that the attackers had made a ransom demand, but the company chose not to pay. SecurityWeek has not independently verified the attackers’ claims.
Related: 153 Million Driver License Images Offered on Dark Web
Related: Ransomware Gang Claims Nutex Health Data Breach
Related: 9.5 Million Impacted by Aesto Health Data Breach