Skip to main content

Ransomware victim disclosure

All victims

Manchester Airports Group

Claimed by Fulcrumsec · listed 3 days ago

3d
Age
since listed · data leaked

Status timeline

  1. ListedSep 1, 2026
  2. Data leakeddate unknown

At a glance

Status
Data leaked
Listed on leak site
Sep 1, 2026

About the victim

AI dossier — public-source company profile

Manchester Airports Group (MAG) is the UK's largest airport operator, owning and managing three major airports: Manchester (third busiest in UK), London Stansted (fourth busiest), and East Midlands. The group served 61.3 million passengers in FY24 across 58 airlines to 261 destinations, and operates CAVU, a digital travel services business.

Industry
Airport Operations & Aviation Services
Address
Manchester, M90 1QX, England

Attack summary

Severity: critical — Confirmed exfiltration at massive scale (550 GB, 8.67 million customer profiles) of highly sensitive PII including full identity, contact details, vehicle registrations, and future travel schedules. Particularly severe exposure of government officials, judges, military personnel, and security-sensitive figures whose home absence schedules are now public. Data enables physical security threats (burglary, stalking) and targeting of sensitive personnel. Group explicitly withheld ~200,000 future tra

fulcrumsec claims to have exfiltrated ~550 GB of customer data via exposed Iterable API keys hardcoded in the JavaScript of all three airports' websites. The breach encompasses customer profiles, booking records, vehicle registrations, SMS communications, marketing configurations, and travel schedules for approximately 8.67 million customers, with data published in full.

critical

Data the group says was taken

AI dossier — extracted from the leak post
  • 8.67 million customer profiles with name, email, mobile, home town, postal region, residential IP
  • 1.17 billion customer events including email sends, opens, clicks, subscribes, unsubscribes, bounces, complaints
  • 2.48 million parking, lounge, and fast-track purchase records totalling £83.4 million in transactions
  • 108,077 UK vehicle registration plates linked to owner identity and airport parking bookings
  • 190,849 future travel bookings dated September 2026 or later with vehicle and date information
  • Marketing campaigns, journeys, lists, segments, and email templates in live JSON format
  • Full platform configurations for three airports
  • Records of public figures including parliamentarians, judges, government officials, military, athletes, media, and NHS staff

Original description

AI-summarised, not from the leak post

Manchester Airports Group (MAG) is a UK-based airport operator and one of the largest in the United Kingdom. It owns and operates Manchester Airport, London Stansted Airport, and East Midlands Airport. Operating within the aviation and transportation infrastructure industry, MAG handles millions of passengers annually, providing terminal management, retail, and ground handling services across its portfolio of airports throughout England.

The leak post

captured from the group's site
Manchester Airports Group (MAG) • Aviation • ~549 GB
8,672,291 customer profiles • 1.169 billion events • 108,077 vehicle registrations • 190,849 bookings dated 1 September 2026 or later • 2,482,763 purchase events • 461,433 rendered SMS • 1,672 company addresses inside the passenger data • the full configuration of three marketing projects
The dataset is four tar.gz archives, one per airport plus the customer database. Every number in this post can be checked against them.  
| Stansted — 603,251,950 events, 1,219,248 purchases, 203,351 SMS, 6 campaigns, 37 lists, 50 journeys, full platform configuration  |  
| --- |  
| Manchester — 484,020,700 events, 1,134,372 purchases, 239,745 SMS, 30 campaigns, 28 lists, 35 journeys, full platform configuration  |  
| East Midlands — 82,030,161 events, 129,143 purchases, 18,337 SMS, 6 campaigns, 15 lists, 10 journeys, full platform configuration  |  
| The customer database — 8,672,291 profiles: Manchester 4,387,221, Stansted 3,530,009, East Midlands 755,061  |  
Uncompressed, the total data adds up to 550 GB.
Today we are releasing the Manchester Airports Group dataset: every customer, event, configuration that serves Manchester Airport, Lon…

Sources

Source

Indexed 3 days ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About fulcrumsec

FulcrumSec is a recently emerged ransomware group that was first observed in May 2026, operating with apparent financial motivations based on their targeting patterns across multiple countries and high-value sectors. Given the recency of their emergence and limited public documentation, the group's specific country of origin and potential affiliations remain unclear, though their targeting of victims across the United States, India, Netherlands, Colombia, and Japan suggests either a geographically distributed operation or deliberate international scope rather than nation-state backing. The group has demonstrated a preference for targeting technology companies, business services firms, and healthcare organizations, with 21 documented victims indicating a selective approach focused on sectors likely to yield significant ransom payments due to operational dependencies and sensitive data holdings. Their attack methodology details remain largely undocumented in public threat intelligence reports from major security firms, though their sector targeting suggests sophisticated initial access capabilities given the typically robust security postures of technology and healthcare organizations. No major high-profile campaigns or significant law enforcement actions against FulcrumSec have been publicly reported by CISA, FBI, or leading cybersecurity researchers as of available intelligence. The group appears to remain active as of the most recent observations, though the limited public intelligence on their operations suggests they may be maintaining a relatively low profile compared to more established ransomware enterprises. The group has been linked to 26 public disclosures across our corpus. First observed on a leak site on May 1, 2026; most recent post September 1, 2026. The operation is currently active.

Timeline of this disclosure

  • September 1, 2026Manchester Airports Group listed by fulcrumsecon the group's public leak site

Sector and geography

This disclosure adds to ransomware activity in the Transportation sector, which has 47 disclosures indexed across all operators we track. Geographically, Manchester Airports Group is reported in United Kingdom, a country with 377 ransomware disclosures in our corpus.

If your organisation is affected

A listing by fulcrumsec means Manchester Airports Group appeared on a ransomware extortion site and data attributed to it has been published. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Report the incident to your national CERT, NCSC (United Kingdom), as required for your jurisdiction.
  • Monitor for the data appearing on fulcrumsec's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.