Hackers have published data allegedly stolen from Manchester Airports Group (MAG) after the UK’s largest airport operator refused to pay a ransom following a major cyberattack.
The breach affects Manchester Airport, London Stansted Airport and East Midlands Airport, all operated by MAG. The company disclosed the incident on August 27th, confirming that an unauthorized third party had accessed information associated with approximately 8.7 million customers.
The attackers, operating under the name FulcrumSec, have now claimed to have released the complete dataset obtained during the intrusion. According to the group, the stolen database contains 8,672,291 customer profiles, more than 2.48 million purchase records, 461,433 SMS messages and 108,077 vehicle registrations. It also allegedly contains future booking information, platform configuration data and more than 1.1 billion marketing events.
MAG previously confirmed that compromised information includes email addresses, telephone numbers, postcodes and vehicle registration numbers. The records originated from services such as airport WiFi registrations and bookings for parking, lounges and Fast Track access.
However, the company said the affected systems did not contain customers’ banking or payment information. MAG also noted that the vast majority of affected individuals had only their email addresses exposed.
The cyberattack did not interfere with flights or other airport operations. Passenger safety and aviation security were not affected, and parking services continued operating normally. MAG restricted access to affected systems after discovering the incident and brought in cybersecurity specialists while notifying relevant authorities.
FulcrumSec reportedly demanded money in exchange for the stolen information, but MAG refused to pay. The attackers subsequently published the data while claiming that they had removed some of its most sensitive contents before making it available.
The group also alleges that records belonging to politicians, military personnel and other public figures were included in the stolen database. Those claims have not been independently confirmed.
FulcrumSec has additionally provided its own explanation of how it obtained access, claiming that security-related keys were exposed through MAG’s public-facing website and could be viewed without sophisticated reconnaissance. This account comes directly from the attackers and has not been confirmed by MAG.
The disclosure expands what was initially known about the incident. When MAG first announced the breach, the identity of the attackers was unclear, and there was no public evidence that the stolen database had been released.
MAG has advised affected customers to remain cautious about unexpected emails, phone calls and text messages. The combination of contact information, vehicle registrations and travel-related records could potentially make convincing targeted scams easier to construct.
FulcrumSec describes itself as a financially motivated data-extortion operation that steals corporate information and threatens publication to pressure victims into paying. The group has previously claimed responsibility for attacks involving other major organizations.
With the ransom rejected, the MAG incident has now moved from an acknowledged theft of customer information to the public release of millions of allegedly stolen records.