
Hacking group FulcrumSec has claimed responsibility for a recent cyberattack on Manchester Airports Group, in which the sensitive personal data of an estimated 8.7 million people was compromised.
On August 27, in a data security notice published on its website, MAG said that it was a victim of a data security incident where threat actors gained unauthorised access to its internal network. The company launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
While the full details of the incident wasn’t shared initially, MAG said that a quantity of customer data relating to car park, lounge and Fast Track bookings, as well as in-airport Wi-Fi sign-ups, was obtained at Manchester, Stansted and East Midlands airports.
The company said the incident had not compromised passenger safety or aviation security and had caused no disruption to airport operations. It added that all airport services remain operational, with customer parking facilities continuing to function as normal.
While MAG did not initially disclose the number of individuals affected, a company spokesperson said that the group had identified up to 8.7 million customers whose data may have been impacted by the incident. MAG cautioned that the figure could rise as its investigation into the breach continues.
Recently, FulcrumSec hacker group has claimed responsibility for the cyber attack on MAG, and said it has stolen approximately 86 GB of confidential data from the company.
According to BleepingComputer, the records were verified against a traveller’s Manchester Airport purchase history, confirming previous Fast Track bookings, arrival times, terminal details, payments, references, total spending, and trip purpose. The leaked data reportedly included a 21.5 GB customer database containing personal identifiers, booking history, and marketing classifications.
FulcrumSec claimed that it gained access using Manchester Airport-specific Iterable API credentials exposed in client-side JavaScript. According to the group, the compromised dataset includes nearly 200,000 upcoming travel records for the remainder of 2026, containing travel dates, times, booking details, and associated personally identifiable information.
The UK Information Commissioner’s Office (ICO) said that MAG had formally notified the regulator about the incident. The ICO said it was currently assessing the situation and would consider the circumstances surrounding the data security incident, including the nature and extent of the information involved, before determining whether any further action was necessary.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543