[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fIHuLNG65TDlotFp8whN82j-cGxEXOojHAT3LIzlSXjE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"2bc430de-9f6d-4dbf-8cda-644240d249b0","exposed-admin-keys-in-public-javascript-led-to-88m-record-breach-at-manchester-airports","7993e066-f503-449d-b717-4a69dcc4b70f","Exposed Admin Keys in Public JavaScript Led to 8.8M Record Breach at Manchester Airports","The root failure here was a critical secrets management error: administrative API keys or credentials were embedded directly in client-side JavaScript, making them publicly accessible to anyone who inspected the website's source code. This is a fundamental configuration management failure that effectively handed attackers the keys to the kingdom without requiring any sophisticated exploitation. The breach highlights how a single developer oversight in handling secrets can cascade into a massive data exposure affecting millions of individuals. MAG's refusal to pay the ransom, while principled, underscores that organisations must invest in prevention rather than relying on post-breach negotiations. The publication of 550GB of personal data now exposes those 8.8 million individuals to identity theft, phishing, and fraud for years to come.","**Immediate actions:**\n- Audit all frontend JavaScript, mobile app bundles, and public-facing web assets immediately to identify and rotate any exposed credentials, API keys, or tokens.\n- Rotate all potentially compromised admin keys and secrets across every system that shared those credentials without waiting to confirm scope.\n- Engage a threat intelligence service to monitor dark web and leak sites for published data to enable timely notification to affected individuals.\n\n**Long-term improvements:**\n- Implement a dedicated secrets management solution (e.g., HashiCorp Vault, AWS Secrets Manager) to ensure credentials are never hardcoded into source code or build artifacts.\n- Enforce pre-commit hooks and CI\u002FCD pipeline scanning tools (e.g., GitGuardian, TruffleHog) to automatically block secrets from being committed to repositories or deployed to frontends.\n- Adopt a principle of least privilege for all admin keys, scoping permissions to the minimum required function and enforcing short-lived, auto-rotating credentials.\n\n**Detection measures:**\n- Deploy continuous automated scanning of all publicly accessible web assets to detect newly introduced secret leakage before attackers discover it.\n- Implement SIEM alerting on anomalous admin-level API activity, particularly large data access or export operations outside of business hours.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 3: Data Protection","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 16: Application Software Security","NIST SP 800-53 IA-5: Authenticator Management","NIST SP 800-53 SA-15: Development Process, Standards, and Tools","NIST SP 800-53 AC-3: Access Enforcement","NIST CSF DE.CM-8: Vulnerability Scans","OWASP ASVS V6: Stored Cryptography \u002F Secrets Management","GDPR Article 25: Data Protection by Design and by Default","GDPR Article 32: Security of Processing","GDPR Article 33: Notification of a Personal Data Breach","published","2026-09-03T16:20:25.222615+00:00","2026-09-03T16:20:24.88+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.securityweek.com\u002Fmanchester-airports-group-data-on-8-8-million-people-leaked-after-ransom-refusal\u002F","manchester-airports-group-data-on-8-8-million-people-leaked-after-ransom-refusal-ccbb70","Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":44,"name":45,"slug":46,"description":47,"color":48},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]