[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$frJ1Q5dhJOA_XKOBsBXXgE3I2PeOih09XUTZbtj7BzQM":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"7993e066-f503-449d-b717-4a69dcc4b70f","Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal","manchester-airports-group-data-on-8-8-million-people-leaked-after-ransom-refusal-ccbb70","Hacker group published roughly 550GB of data after MAG reportedly refused to pay a ransom demand; the group says it gained access via exposed admin keys. The post Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal appeared first on SecurityWeek.","The FulcrumSec extortion gang has published approximately 550GB of data allegedly stolen from Manchester Airports Group (MAG) after MAG reportedly refused to pay a ransom demand. The leaked data includes personal information of around 8.8 million individuals, such as names, email addresses, phone numbers, vehicle registrations, and IP addresses. The attackers claim they gained access by exploiting exposed admin keys found in the frontend JavaScript of the airports' websites.","Manchester Airports Group data leak impacts 8.8 million people after ransom refusal.","Data allegedly stolen from the Manchester Airports Group (MAG) and leaked online this week includes the email addresses and phone numbers of 8.8 million people. MAG disclosed the incident last week, warning that hackers had breached its systems, stealing car park, lounge, and Fast Track booking data, along with in-airport Wi-Fi sign-ups at the Manchester, London Stansted, and East Midlands airports. The airport operator disclosed that hackers had exfiltrated email addresses, phone numbers, vehicle registrations, and postcodes, noting that its operations were not affected by the incident. MAG confirmed that the stolen information was stored in a database hosted by a third party and that it received a ransom demand from the attackers, but refrained from sharing further details on the matter. Over the weekend, the FulcrumSec extortion gang claimed responsibility for the attack and has since published roughly 550 gigabytes of uncompressed data allegedly stolen from MAG. The data, the group says, includes the personal information of roughly 8.7 million individuals, including names, emails, phone numbers, town and postal region, and residential IP addresses used to access accounts. According to data breach notification site HaveIBeenPwned, which parsed the dataset and added it to its database, approximately 8.8 million email addresses and phone numbers were compromised. Names, browser agent details, purchases, and vehicle registration plates were also exposed.Advertisement. Scroll to continue reading. FulcrumSec says the stolen data includes 2,482,763 purchases (bookings for parking, lounge, and fast-track products), 461,433 SMS messages associated with bookings, car park, and vehicle registration, and 108,077 unique UK vehicle registration plates. Additionally, the extortion group claims to have exfiltrated MAG platform’s configuration. SecurityWeek has not independently verified the attackers’ claims. FulcrumSec says it breached MAG’s systems using admin keys that were left in plain sight “in the frontend JavaScript of each of its three airports’ websites”, in each root domain. The extortion group has admitted that MAG did not pay a ransom. Related: 153 Million Driver License Images Offered on Dark Web Related: Ransomware Gang Claims Nutex Health Data Breach Related: 9.5 Million Impacted by Aesto Health Data Breach Related: Berlin Won’t Pay Extortion Group Claiming Data Theft Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Exploit Published for Fresh Cleo Harmony VulnerabilityMalicious Virtualizor Update Served via BGP HijackingChrome and Firefox Updates Patch Dozens of Vulnerabilities23-Year-Old Sality P2P Botnet DisruptedHackers Start Exploiting Critical Langflow VulnerabilityFive Venezuelans Plead Guilty in US Court to ATM JackpottingRansomware Gang Claims Nutex Health Data Breach9.5 Million Impacted by Aesto Health Data Breach Latest News Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue AgentsHiddenLayer Raises $100 Million for AI Runtime SecurityAI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million153 Million Driver License Images Offered on Dark WebOver 3 Million WordPress Sites Affected by Migration Plugin VulnerabilityCisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch VulnerabilitiesOpenLeash Adds a Human Check to Risky AI Agent ActionsUK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveTom Bonos has been named Chief Revenue Officer at Sumo Logic.Axonius has appointed Chris Jones as CTSO and Dan Schoenbaum as SVP of Business Development.Optiv has appointed Sean Forkan as Chief Revenue Officer (CRO).More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fmanchester-airports-group-data-on-8-8-million-people-leaked-after-ransom-refusal\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2025\u002F07\u002FFraud-Cybercrime-AI.jpeg","2026-09-03T15:35:19+00:00","2026-09-03T16:00:09.727462+00:00",8,[18,21],{"name":19,"type":20},"Manchester Airports Group","vendor",{"name":22,"type":23},"FulcrumSec","threat_actor","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":24,"icon":26,"name":27,"slug":28},null,"Breaches","breaches",[30,32,37,42],{"category":31},{"id":24,"icon":26,"name":27,"slug":28},{"category":33},{"id":34,"icon":26,"name":35,"slug":36},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":38},{"id":39,"icon":26,"name":40,"slug":41},"7d8b5ab8-ea0b-4ced-ae97-ec251b86993a","Ransomware","ransomware",{"category":43},{"id":44,"icon":26,"name":45,"slug":46},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[48],{"type":49,"value":22,"context":50},"malware","Ransomware\u002Fextortion gang claiming responsibility for the attack."]