MAG data leak exposes 8.8M emails, phones after ransom refused

Hackers published about 550GB of Manchester Airports Group data after a ransom was refused, exposing roughly 8.8 million email addresses, phone numbers and booking and Wi-Fi sign-up records.

Hackers published roughly 550GB of data after Manchester Airports Group (MAG) refused to pay a ransom. The files include about 8.8 million email addresses and phone numbers and records from car park, lounge and Fast Track bookings and in-terminal Wi‑Fi sign-ups across Manchester, London Stansted and East Midlands airports.

MAG disclosed the breach last week and reported attackers accessed systems that held booking and Wi‑Fi sign-up information. The operator reported the stolen fields included email addresses, phone numbers, vehicle registrations and postcodes. MAG confirmed core airport operations were not affected.

MAG confirmed the stolen information was stored in a database hosted by a third party. The company notified affected customers, reported the incident to authorities and is working with cyber security specialists to investigate how credentials or keys were exposed.

An extortion group calling itself FulcrumSec claimed responsibility and published about 550 gigabytes of uncompressed files it says were taken from MAG systems. The group claims the dataset contains personal details for roughly 8.7 million people, 2,482,763 booking purchases for parking, lounges and fast‑track products, 461,433 SMS messages tied to bookings, and 108,077 unique UK vehicle registration plates. FulcrumSec also claims to have copied configuration data for MAG’s platform and to have used administrator keys found in frontend JavaScript on each airport root domain. Those claims have not been independently verified.

Data breach notification service HaveIBeenPwned parsed the files and added them to its database, recording about 8.8 million compromised email addresses and phone numbers. The service allows individuals to check whether their email or phone number appears in the dataset.

MAG confirmed it did not pay a ransom and reported airport services continued without disruption. The company advised customers to follow standard security practices, monitor communications linked to their bookings and review account settings. MAG has not published a full list of exposed records or the time range covered by the data.

Security experts note that leaving sensitive keys or credentials in frontend code can enable unauthorized access. MAG is investigating how the keys were exposed and is coordinating with authorities and external cyber security advisers as it responds to the incident.

Articles by this author