Nor'easter Hits Boston: 4 Airline Waivers Compared
Six days ago, we covered MAG’s confirmation that hackers had stolen data on roughly 8.7 million customers and that MAG had refused to pay the ransom. At the time, the practical risk was theoretical — a criminal group held the data, and whether it ever surfaced publicly was an open question. That question got answered. By September 2, the extortion group FulcrumSec had published the stolen dataset on its leak site, for free, after saying MAG “declined to pay the necessary fee to protect their passengers’ data.”
That changes the math entirely. A breach sitting with one attacker group is bad. A breach freely downloadable by anyone with a BitTorrent client is a different category of bad — every phishing operator, SIM-swap crew, and parking-scam text farm on the internet now has the same access a single ransomware gang used to have exclusively. Here’s what actually got dumped, why it’s worse than the August disclosure suggested, and what to do about it this week.
Quick Verdict
What happened FulcrumSec published the full stolen MAG dataset on its leak site around Sept 1-2, 2026, after MAG refused to pay Who’s affected An estimated 8.7-8.8 million customers of Manchester, Stansted, and East Midlands airports File size ~86GB compressed, roughly 640GB once extracted What’s in it Emails, phone numbers, names, postcodes, vehicle plates, marketing history, and nearly 191,000 upcoming 2026 bookings What’s NOT in it Payment card numbers, bank details, passport data Access Free download — no longer held privately by one group New risk vs. Aug 27 Sharply higher phishing, SIM-swap, and parking-scam exposure, since anyone can now query the data What to do Check Have I Been Pwned, treat any MAG or parking-related text as fake by default, watch for SIM-swap attempts
The initial 86GB figure was compressed. FulcrumSec later told BleepingComputer that the exported files run to roughly 640GB once extracted — which tracks, because flat text and database exports compress hard, and this is a lot of consolidated customer records rather than a handful of big files.
What makes this dump worse than a typical breach isn’t just size. It’s how the records are structured. This isn’t a spreadsheet of emails. According to Infosecurity Magazine’s review of the sample data, the leak includes:
That last category is the one worth sitting with. A breach of past behavior is a privacy problem. A breach that tells someone exactly when you’re flying, from which terminal, months in advance, is a physical-safety problem — the kind of detail that matters if you’re worried about a home being targeted while you’re away, not just a phishing text landing in your inbox.
FulcrumSec claims it stripped “the most sensitive parts” out before publishing, which is a strange thing for a group to say about a dataset it’s simultaneously calling comprehensive. Take that claim for what it’s worth: a group with every incentive to make the leak sound bigger and worse than it is, while also wanting credit for restraint it may not have actually shown.
The access method is almost more alarming than the leak itself. FulcrumSec says it found admin credentials for Iterable — the marketing platform MAG used to run its customer email and SMS campaigns — sitting in plain view in the front-end JavaScript of all three airport websites. Not buried in a config file. Not on an obscure staging subdomain. Visible to anyone who right-clicked “inspect” on manchesterairport.co.uk, stansted.co.uk, or eastmidlandsairport.com.
FulcrumSec isn’t new to this playbook, either — the group has previously claimed breaches at Arup Group and Novo Nordisk using similarly exposed credentials, just buried deeper in those cases. MAG’s mistake was putting the keys somewhere a first-year developer with browser dev tools open could find them. That’s not a sophisticated attack. It’s a company that outsourced its marketing automation to a third-party platform and never audited what that integration exposed on the public-facing side of its sites.
You’re likely affected if any of the following apply to you from roughly the past two to three years:
The fastest way to check is to search your email address on Have I Been Pwned’s Manchester Airports Group breach page, which indexed the leaked dataset. If it comes back positive, assume your phone number, postcode, and — if you ever parked a car there — your vehicle plate are in the same record.
When MAG first confirmed the breach on August 27, the honest read was: this is bad, but it’s contained to one criminal group, and the practical risk depends on what that group decides to do with it. We said as much at the time — treat every MAG-branded text as suspicious, but the sky-is-falling framing some outlets ran with felt premature.
That framing doesn’t hold anymore. A dataset behind one group’s paywall is a risk you can reason about — limited buyers, limited scale, some chance it never gets monetized at all. A dataset published for free on a leak site is a risk with no ceiling. Every low-effort scam operation that would never have paid FulcrumSec’s ransom demand can now pull the file for nothing. That’s the entire reason “public leak” and “private theft” get treated as different tiers of incident in security reporting — the second one caps the damage at whoever paid; the first one doesn’t cap it at all.
Concretely, that means three risks jumped from theoretical to active this week:
Phishing gets more convincing, not less. Scam texts referencing your real name, email, and a parking booking you actually made were already a risk after the August disclosure. Now the pool of people capable of sending them is unbounded instead of limited to one group’s operators.
SIM-swap risk rises. Attackers doing SIM-swap fraud need a target’s phone number tied to enough personal detail — name, address, sometimes a partial account history — to convince a mobile carrier’s support line they’re you. A record with your name, postcode, phone number, and purchase history is close to a starter kit for that call. If you haven’t set up a PIN or extra verification step with your mobile carrier, this is the week to do it.
Parking and toll scam texts get sharper. We flagged this risk in the original post because of the vehicle plate data — a fake “unpaid parking charge” text referencing your actual registration is far more convincing than a generic one. With the full dataset public, that scam can now run at volume instead of being limited to whoever FulcrumSec sold access to.
Your bank details and passport information were not in the original haul and haven’t shown up in this leak either, per MAG’s statement and the outlets that’ve reviewed the sample data. There’s no card to cancel here. This is a social-engineering risk, not a straight fraud-on-your-account risk — which is exactly why steps 2 through 4 matter more than a bank call would.
This is the second time this year we’ve covered a travel company’s customer data ending up somewhere it shouldn’t because of a third-party integration nobody audited. We wrote about Google buying Spirit Airlines’ internal emails and chat logs out of bankruptcy for AI training back in the spring — a different mechanism, same underlying issue: travel companies collect a lot of personal data through conveniences (WiFi sign-ups, marketing lists, loyalty programs) and hold it with less rigor than the sensitivity deserves.
It also isn’t the only active scam vector travelers are dealing with right now. We covered the FBI’s warning about fake FIFA ticket sites built to harvest payment details from people booking World Cup travel, and flagged the same convenience-versus-exposure trade-off in airport guest pass programs that ask for personal data in exchange for skipping a line. If you’re the type of traveler who connects to airport WiFi without a second thought, it’s worth applying the same skepticism we’ve recommended for in-flight WiFi networks generally — a login screen asking for your email is a data collection point first and a convenience second, whether it’s on the ground or in the air.
None of this means stop using airport parking or lounge access. It means treating every sign-up screen at an airport as a place your data can end up in a leak like this one, months or years after you forgot you ever used the service.
MAG refused to pay a ransom, which was defensible on its own terms — paying doesn’t reliably stop a leak, and rewarding extortion invites more of it. But the result is that 8.7 to 8.8 million people’s emails, phone numbers, postcodes, vehicle plates, and in nearly 191,000 cases, future travel plans, are now sitting on a leak site anyone can reach. The risk we described in August as “watch for suspicious texts” is now “assume scammers already have this file and are using it.” Check Have I Been Pwned, lock down your mobile account against SIM-swap attempts, and stay skeptical of anything referencing your booking history for longer than this week’s news cycle lasts.
Details current as of September 5, 2026, based on reporting from BleepingComputer and Infosecurity Magazine. This is an active, developing incident — verify current guidance directly with MAG or the National Cyber Security Centre if you believe you’re affected.