Hackers publish sensitive data of nearly 9 million UK travelers
The attackers claim the theft wasn't even that difficult.

Photo by Peter Byrne/PA Images via Getty Images.
- Hackers published 8.7 million records stolen from Manchester Airports Group, affecting 3 UK airports.
- MAG says the affected systems did not hold bank or payment details, and airport operations were not compromised.
- The stolen data includes emails, phone numbers, postcodes, vehicle registrations, and future booking information.
- FulcrumSec, the group behind the attack, claims visible website keys made the breach easy – MAG refused to pay the ransom.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Hackers behind the breaches at Manchester, London Stansted, and East Midlands airports have reportedly published all 8.7 million records they stole from their operator, the Manchester Airports Group (MAG).
The attackers say some of the stolen records belong to public figures, politicians, and military personnel, warning this could expose victims to burglary, stalking, and other physical threats.
“A quantity of customer data was obtained by an unauthorised third party. Neither MAG nor the system accessed hold customers’ bank or payment details. The data that has been accessed includes customers’ email addresses, phone numbers, vehicle registrations and postcodes,” MAG stated on its website.
A MAG spokesperson told the BBC on Monday that hackers had demanded a ransom fee for the return of the data, but this was refused by the airport group. As per Wednesday’s BBC report, criminals have published all the data they stole from the airports’ operator.
"Today we are releasing the Manchester Group database," hackers said.
In the dark web post, the group has claimed that the stolen material includes:
- 8,672,291 customer profiles
- 1.169 billion marketing events,
- 2,482,763 purchases
- 461,433 SMS messages
- 108,077 vehicle registrations
- Platform configuration data
- Future booking information
MAG, the UK's largest airport operator, disclosed the cyberattack on August 27th, revealing that data from approximately 8.7 million customers was accessed. This included information collected through WiFi registrations and car park, lounge, and Fast Track bookings.
The operator said that no bank or payment information was held on the affected systems and that passenger safety and airport operations had not been compromised.
MAG also stated that the "vast majority" of the 8.7 million affected customers had only their email addresses exposed – which still makes it one of the biggest airport breaches in the UK.
The attackers claimed that it wasn’t a challenge to steal this valuable data.
These [security]keys were not found on some obscure subdomain; any millions of visitors to the site could have right clicked ‘inspect’ and seen the keys just sitting there, plain as day,Threat actor FulcrumSec claims it was simple it was to steal data from MAG
“All 3 of these were on the site’s root domain. No subdomain enumeration or URL crawling necessary," the criminal group added.
FulcrumSec separately said: “Sadly MAG declined to pay the necessary fee to protect their passenger’s data, leaving us to remove the most sensitive parts… from the leak prior to publication.”
Who is FulcrumSec?
Fulcrumsec is a financially motivated data-extortion group that specializes in stealing sensitive corporate information and then threatening to publish it.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The threat actor has previously claimed attacks against Ozempic maker Novo Nordisk and legal data giant LexisNexis.
The group claimed it spent more than 2 months inside Novo Nordisk’s network before allegedly exfiltrating around 1.3TB of data, including information relating to clinical trials, drug development, source code, employees, and AI assets.