Data allegedly stolen from the Manchester Airports Group (MAG) and leaked online this week includes the email addresses and phone numbers of 8.8 million people.
MAG disclosed the incident last week, warning that hackers had breached its systems, stealing car park, lounge, and Fast Track booking data, along with in-airport Wi-Fi sign-ups at the Manchester, London Stansted, and East Midlands airports.
The airport operator disclosed that hackers had exfiltrated email addresses, phone numbers, vehicle registrations, and postcodes, noting that its operations were not affected by the incident.
MAG confirmed that the stolen information was stored in a database hosted by a third party and that it received a ransom demand from the attackers, but refrained from sharing further details on the matter.
Over the weekend, the FulcrumSec extortion gang claimed responsibility for the attack and has since published roughly 550 gigabytes of uncompressed data allegedly stolen from MAG.
The data, the group says, includes the personal information of roughly 8.7 million individuals, including names, emails, phone numbers, town and postal region, and residential IP addresses used to access accounts.
According to data breach notification site HaveIBeenPwned, which parsed the dataset and added it to its database, approximately 8.8 million email addresses and phone numbers were compromised. Names, browser agent details, purchases, and vehicle registration plates were also exposed.
FulcrumSec says the stolen data includes 2,482,763 purchases (bookings for parking, lounge, and fast-track products), 461,433 SMS messages associated with bookings, car park, and vehicle registration, and 108,077 unique UK vehicle registration plates.
Additionally, the extortion group claims to have exfiltrated MAG platform’s configuration. SecurityWeek has not independently verified the attackers’ claims.
FulcrumSec says it breached MAG’s systems using admin keys that were left in plain sight “in the frontend JavaScript of each of its three airports’ websites”, in each root domain.
The extortion group has admitted that MAG did not pay a ransom.
Related: 153 Million Driver License Images Offered on Dark Web
Related: Ransomware Gang Claims Nutex Health Data Breach
Related: 9.5 Million Impacted by Aesto Health Data Breach
Related: Berlin Won’t Pay Extortion Group Claiming Data Theft


