MAG Confirms Customer Data Breach, FulcrumSec Claims It Obtained 86 GB

Manchester Airports Group confirmed a cyber incident involving leaked customer data. The FulcrumSec group claimed responsibility, but its claims about the volume and scope of the data remain only partially verified.

The MAG data breach affected passenger customer data from three British airports. Manchester Airports Group (MAG) confirmed on August 27, 2026, that an unauthorized third party obtained data belonging to customers of Manchester, London Stansted, and East Midlands airports. The FulcrumSec group claimed responsibility for the cyber incident, while BleepingComputer independently verified some of its claims.

According to MAG, the affected data includes email addresses, phone numbers, vehicle registration numbers, and postal codes. According to the operator, the compromised system did not contain banking or payment information.

The MAG data breach did not affect airport operations

MAG said the incident did not disrupt passenger safety, aviation security, or airport operations themselves. The company also temporarily restricted the Manage My Booking online service as a precaution.

According to BleepingComputer, the operator contacted affected customers, including people with future reservations. The published information does not specify the number of people contacted or the total number of affected records.

FulcrumSec submitted a sample, but the full scope is unconfirmed

In communications with BleepingComputer, the FulcrumSec group said it stole approximately 86 GB of data in the attack. The publication verified one of the records submitted by the group by comparing it with a specific passenger’s known purchase history. This verification supports the credibility of the claim that the group had access to at least some customer data.

However, this does not confirm the claimed volume of 86 GB or the full scope of the breach. MAG has not publicly confirmed this volume, and BleepingComputer was unable to independently verify the entire data exfiltration.

FulcrumSec’s claim of approximately 200,000 records relating to future trips has likewise not been independently confirmed. The group’s described method of gaining access also remains unverified—allegedly through Iterable API credentials embedded in client-side JavaScript.

Targeted scams against passengers are a risk

Although MAG has not reported a leak of payment information, the combination of confirmed contact details and the context of future reservations could increase the risk of targeted scams. Passengers may receive convincing phishing emails, text messages, or phone calls posing as communications from an airport or reservation service.

BleepingComputer said the samples also suggest a broader range of data, such as reservation information, prices, purchase history, IP addresses, and device details. However, MAG has not publicly confirmed these specific categories, so they cannot be considered a verified scope of the incident.

Affected customers should be more cautious with messages concerning flights, reservation changes, refunds, or additional payments. Sensitive actions should be performed directly through official websites and apps, rather than through links delivered by email or text message.

What happens next

Further developments will depend mainly on a more detailed statement from MAG about the volume and types of stolen data. Attention will also focus on any potential investigation by the UK Information Commissioner’s Office (ICO) or law enforcement authorities.

It remains unclear whether FulcrumSec will publish additional data or technical details. MAG may also issue new guidance for affected customers and announce the full restoration of the Manage My Booking service.

Sources

  • Manchester Airport / Manchester Airports Group – Confirms the incident, the basic categories of affected data, the absence of payment information, unaffected operations, and the measures taken.
  • BleepingComputer – Documents FulcrumSec’s claim of responsibility and the partial verification of a sample, while explicitly stating which claims about the scope and access could not be independently confirmed.

Verified and updated: 08/30/2026 19:08

Sharing