Manchester Airports Group: FulcrumSec leaks ~550GB / HIBP ~8.8M emails and phones after ransom refusal
MAG’s 27 August 2026 statement said an unauthorised third party obtained customer data from car park, lounge and Fast Track bookings and in-airport Wi-Fi sign-ups at Manchester, London Stansted and East Midlands airports (emails, phones, vehicle registrations, postcodes; no bank details; operations unaffected). SecurityWeek (3 September 2026) reports the FulcrumSec extortion group published roughly 550GB of uncompressed data after MAG reportedly refused a ransom, claiming access via exposed admin keys. Have I Been Pwned, which ingested the dump, put the scale at about 8.8 million email addresses and phone numbers, with names, browser agents, purchases and vehicle plates also present. FulcrumSec claimed on the order of 2.48 million purchases in the set. MAG’s original mediacentre statement remains the operator notice; treat FulcrumSec/HIBP figures as leak-site and breach-notification telemetry refining scope.
- Exploited in Australia?
- unknown
Primary: MAG statement (27 Aug 2026) · Vendor: MAG customer FAQ · SecurityWeek (3 Sep 2026; FulcrumSec leak / HIBP 8.8M)
