Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Data Breaches » Cyberattack on Major UK Airports Exposes Data of 8.7 Million Customers

Cyberattack on Major UK Airports Exposes Data of 8.7 Million Customers

Last updated:August 31, 2026
Human Written
  • FulcrumSec claims it stole about 86 GB of data from Manchester Airports Group.

  • The group says the data includes detailed booking, parking and travel records.

  • MAG confirms a breach affecting about 8.7 million customers but has not confirmed the wider claims.

Manchester Airports Group Breach Allegedly Exposes 8 7 Million Customers

Manchester Airports Group (MAG) faces new questions about the size of a major customer data breach. Extortion group FulcrumSec claims it carried out the attack. The group says it stole about 86 GB of data from MAG.

The alleged haul goes far beyond the basic customer details MAG first disclosed. FulcrumSec reportedly says the stolen files include customer profiles, past bookings and data linked to future trips.

MAG has confirmed the cyberattack and says about 8.7 million customers were affected. But the airport group has not confirmed the 86 GB figure or the full scope claimed by FulcrumSec.

FulcrumSec Claims 86 GB of Stolen Data

MAG disclosed the breach on August 27. The company said an unknown party took customer data from Manchester, London Stansted and East Midlands airports. The data came from car park, lounge, and Fast Track bookings. It also came from airport Wi-Fi sign-ups.

MAG said the exposed data includes email addresses, phone numbers, vehicle registration numbers and postcodes. The company said the affected system did not hold customers’ bank or payment details.

According to reports, about 8.7 million customers were affected. Most of those customers had only their email addresses exposed, according to the company. Many of those addresses came from airport Wi-Fi sign-ups.

FulcrumSec now claims the breach reached much deeper into MAG’s customer data. The group says it stole about 86 GB of files. It claims one Manchester customer file alone contains about 21.5 GB of data. That file allegedly combines customer profiles with past bookings and marketing information.

FulcrumSec also claims it obtained nearly 200,000 records linked to upcoming travel. The group says those records cover trips planned for the rest of 2026. It claims the records contain travel dates, times, and booking details linked to personal information. MAG has not confirmed those figures or the wider claims.

The scale of the MAG breach is dwarfed by another dark web claim. In August 2026, a threat actor advertised a database of 107 million records allegedly stolen from Iranian travel agencies, including name, nationality, gender, and in some cases, phone numbers and passport numbers. That claim has not been independently verified, but it fits a wider pattern of travel industry databases being targeted by cybercriminals.

The Alleged Data Includes Travel History

The claims raise concern because detailed travel data can help criminals build better scams. The alleged records include booking references, airport and product choices, prices and discounts.

Also, according to reports, they show booking status, parking dates and times, past spending and customer activity. Some of the records allegedly contain IP addresses, rough location data and device details. If accurate, the data could give criminals a clear view of a customer’s past airport activity.

It could also help them spot people with upcoming trips. That information could make fake messages much harder to detect. A scammer could send a message about a parking booking that a customer really made.

The message could name the right airport, date or service. That level of detail could make a fake email or text seem genuine. It could also help criminals pose as MAG or another travel service. 

MAG has warned affected customers to watch for strange emails, calls and text messages.

FulcrumSec Points to Exposed API Keys

FulcrumSec says it gained access through airport-specific Iterable API credentials. The group claims those credentials appeared in code sent to web browsers.

Iterable provides software that businesses use for customer data and marketing. If the claim proves correct, the exposed keys may have given attackers a way to access customer data.

However, MAG hasn’t confirmed whether this was really how the attackers got in. The company says it’s looking into the breach with the help of external experts and the relevant authorities.

Security Affairs also reported FulcrumSec’s claim about the exposed API credentials. The report did not confirm the attack path as an established fact.

Airport Operations were not Affected

Despite the size of the breach, MAG says the attack did not disrupt airport operations. Passenger safety and aviation security were not affected. Customer parking services also continued to run normally.

MAG temporarily stopped access to its Manage My Booking service as a safety step. The company has contacted affected customers. It has also reached out to people with upcoming bookings.

The UK’s National Cyber Security Centre is working with MAG on the response. The Information Commissioner’s Office has also been notified. 

Also, MAG confirmed that the incident did not involve ransomware. The attackers did make an extortion demand, but MAG did not pay it, The Register reported.

Customers Face a Higher Risk of Scams

The stolen data could be useful for phishing and impersonation attacks. An email address alone can support a simple scam. A phone number, postcode and vehicle number give criminals more details.

Booking information can make a fake message look even more real. A criminal could mention a real parking date or Fast Track booking. They could also use a real airport or travel date in a fake message. That may make it harder for customers to spot the fraud.

MAG has urged customers to take extra care with unexpected emails, calls and texts. The company says it will never unexpectedly ask customers for payment or banking details.

Customers should avoid links in unexpected messages. They should contact MAG through its official website if they need to check a booking.

For now, the breach affecting about 8.7 million customers is confirmed. The wider data theft claimed by FulcrumSec is not. The 86 GB data theft claim, the alleged 21.5 GB customer file and nearly 200,000 future travel records still need confirmation. MAG’s investigation should reveal how the attackers got in and exactly what data they took.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.