Hero image for Manchester Airport Breach: Your Data Is Now Public
By Travel Tools Guide Team

Manchester Airport Breach: Your Data Is Now Public


Six days ago, we covered MAG’s confirmation that hackers had stolen data on roughly 8.7 million customers and that MAG had refused to pay the ransom. At the time, the practical risk was theoretical — a criminal group held the data, and whether it ever surfaced publicly was an open question. That question got answered. By September 2, the extortion group FulcrumSec had published the stolen dataset on its leak site, for free, after saying MAG “declined to pay the necessary fee to protect their passengers’ data.”

That changes the math entirely. A breach sitting with one attacker group is bad. A breach freely downloadable by anyone with a BitTorrent client is a different category of bad — every phishing operator, SIM-swap crew, and parking-scam text farm on the internet now has the same access a single ransomware gang used to have exclusively. Here’s what actually got dumped, why it’s worse than the August disclosure suggested, and what to do about it this week.

Quick Verdict

What happenedFulcrumSec published the full stolen MAG dataset on its leak site around Sept 1-2, 2026, after MAG refused to pay
Who’s affectedAn estimated 8.7-8.8 million customers of Manchester, Stansted, and East Midlands airports
File size~86GB compressed, roughly 640GB once extracted
What’s in itEmails, phone numbers, names, postcodes, vehicle plates, marketing history, and nearly 191,000 upcoming 2026 bookings
What’s NOT in itPayment card numbers, bank details, passport data
AccessFree download — no longer held privately by one group
New risk vs. Aug 27Sharply higher phishing, SIM-swap, and parking-scam exposure, since anyone can now query the data
What to doCheck Have I Been Pwned, treat any MAG or parking-related text as fake by default, watch for SIM-swap attempts

What FulcrumSec Actually Published

The initial 86GB figure was compressed. FulcrumSec later told BleepingComputer that the exported files run to roughly 640GB once extracted — which tracks, because flat text and database exports compress hard, and this is a lot of consolidated customer records rather than a handful of big files.

What makes this dump worse than a typical breach isn’t just size. It’s how the records are structured. This isn’t a spreadsheet of emails. According to Infosecurity Magazine’s review of the sample data, the leak includes:

  • Nearly 8.7 million customer profiles — email, name, mobile number, hometown, postcode, residential IP address
  • Roughly 1.2 billion marketing events (email sends, opens, clicks)
  • About 2.5 million historical purchases across parking, Fast Track, and lounge bookings
  • Over 461,000 SMS messages containing booking and vehicle details in plain text
  • Around 108,000 vehicle registration plates
  • Nearly 191,000 future bookings for the rest of 2026, including travel dates and terminal details

That last category is the one worth sitting with. A breach of past behavior is a privacy problem. A breach that tells someone exactly when you’re flying, from which terminal, months in advance, is a physical-safety problem — the kind of detail that matters if you’re worried about a home being targeted while you’re away, not just a phishing text landing in your inbox.

FulcrumSec claims it stripped “the most sensitive parts” out before publishing, which is a strange thing for a group to say about a dataset it’s simultaneously calling comprehensive. Take that claim for what it’s worth: a group with every incentive to make the leak sound bigger and worse than it is, while also wanting credit for restraint it may not have actually shown.

How They Got In

The access method is almost more alarming than the leak itself. FulcrumSec says it found admin credentials for Iterable — the marketing platform MAG used to run its customer email and SMS campaigns — sitting in plain view in the front-end JavaScript of all three airport websites. Not buried in a config file. Not on an obscure staging subdomain. Visible to anyone who right-clicked “inspect” on manchesterairport.co.uk, stansted.co.uk, or eastmidlandsairport.com.

FulcrumSec isn’t new to this playbook, either — the group has previously claimed breaches at Arup Group and Novo Nordisk using similarly exposed credentials, just buried deeper in those cases. MAG’s mistake was putting the keys somewhere a first-year developer with browser dev tools open could find them. That’s not a sophisticated attack. It’s a company that outsourced its marketing automation to a third-party platform and never audited what that integration exposed on the public-facing side of its sites.

Am I Affected by the Manchester Airport Data Leak?

You’re likely affected if any of the following apply to you from roughly the past two to three years:

  1. You booked parking at Manchester, Stansted, or East Midlands airports through the airport’s own website or app.
  2. You bought Fast Track or a lounge pass at any of the three airports.
  3. You signed up for free in-airport WiFi, trading an email for a login screen.
  4. You’re on MAG’s marketing email or SMS list, even if you never made a purchase.
  5. You have a booking for later in 2026 at any of the three airports — you may be in the roughly 191,000 future-travel records specifically.

The fastest way to check is to search your email address on Have I Been Pwned’s Manchester Airports Group breach page, which indexed the leaked dataset. If it comes back positive, assume your phone number, postcode, and — if you ever parked a car there — your vehicle plate are in the same record.

Why This Is Worse Than the August Disclosure

When MAG first confirmed the breach on August 27, the honest read was: this is bad, but it’s contained to one criminal group, and the practical risk depends on what that group decides to do with it. We said as much at the time — treat every MAG-branded text as suspicious, but the sky-is-falling framing some outlets ran with felt premature.

That framing doesn’t hold anymore. A dataset behind one group’s paywall is a risk you can reason about — limited buyers, limited scale, some chance it never gets monetized at all. A dataset published for free on a leak site is a risk with no ceiling. Every low-effort scam operation that would never have paid FulcrumSec’s ransom demand can now pull the file for nothing. That’s the entire reason “public leak” and “private theft” get treated as different tiers of incident in security reporting — the second one caps the damage at whoever paid; the first one doesn’t cap it at all.

Concretely, that means three risks jumped from theoretical to active this week:

Phishing gets more convincing, not less. Scam texts referencing your real name, email, and a parking booking you actually made were already a risk after the August disclosure. Now the pool of people capable of sending them is unbounded instead of limited to one group’s operators.

SIM-swap risk rises. Attackers doing SIM-swap fraud need a target’s phone number tied to enough personal detail — name, address, sometimes a partial account history — to convince a mobile carrier’s support line they’re you. A record with your name, postcode, phone number, and purchase history is close to a starter kit for that call. If you haven’t set up a PIN or extra verification step with your mobile carrier, this is the week to do it.

Parking and toll scam texts get sharper. We flagged this risk in the original post because of the vehicle plate data — a fake “unpaid parking charge” text referencing your actual registration is far more convincing than a generic one. With the full dataset public, that scam can now run at volume instead of being limited to whoever FulcrumSec sold access to.

What to Do This Week

  1. Search your email on Have I Been Pwned to confirm whether you’re in the leaked set.
  2. Call your mobile carrier and add a SIM-swap PIN or extra verification step, if you haven’t already. This is the single highest-value action given what’s in this specific leak.
  3. Treat any text or email referencing a parking fine, toll charge, or MAG account issue as fake by default, even if it names your actual car registration or a real past booking. That detail no longer proves it’s legitimate — it just proves the sender has the leaked file.
  4. Don’t click links in unexpected MAG, airport parking, or “manage your booking” messages. Go to the airport’s site directly if you need to check anything.
  5. If you have an upcoming 2026 booking at any of the three airports, be extra cautious about messages referencing that specific trip — you may be in the future-bookings portion of the leak, which gives scammers dates and terminal details to work with.
  6. Report anything suspicious to Action Fraud, the UK’s national fraud reporting service, rather than replying to or engaging with the sender.

Your bank details and passport information were not in the original haul and haven’t shown up in this leak either, per MAG’s statement and the outlets that’ve reviewed the sample data. There’s no card to cancel here. This is a social-engineering risk, not a straight fraud-on-your-account risk — which is exactly why steps 2 through 4 matter more than a bank call would.

The Bigger Pattern

This is the second time this year we’ve covered a travel company’s customer data ending up somewhere it shouldn’t because of a third-party integration nobody audited. We wrote about Google buying Spirit Airlines’ internal emails and chat logs out of bankruptcy for AI training back in the spring — a different mechanism, same underlying issue: travel companies collect a lot of personal data through conveniences (WiFi sign-ups, marketing lists, loyalty programs) and hold it with less rigor than the sensitivity deserves.

It also isn’t the only active scam vector travelers are dealing with right now. We covered the FBI’s warning about fake FIFA ticket sites built to harvest payment details from people booking World Cup travel, and flagged the same convenience-versus-exposure trade-off in airport guest pass programs that ask for personal data in exchange for skipping a line. If you’re the type of traveler who connects to airport WiFi without a second thought, it’s worth applying the same skepticism we’ve recommended for in-flight WiFi networks generally — a login screen asking for your email is a data collection point first and a convenience second, whether it’s on the ground or in the air.

None of this means stop using airport parking or lounge access. It means treating every sign-up screen at an airport as a place your data can end up in a leak like this one, months or years after you forgot you ever used the service.

The Bottom Line

MAG refused to pay a ransom, which was defensible on its own terms — paying doesn’t reliably stop a leak, and rewarding extortion invites more of it. But the result is that 8.7 to 8.8 million people’s emails, phone numbers, postcodes, vehicle plates, and in nearly 191,000 cases, future travel plans, are now sitting on a leak site anyone can reach. The risk we described in August as “watch for suspicious texts” is now “assume scammers already have this file and are using it.” Check Have I Been Pwned, lock down your mobile account against SIM-swap attempts, and stay skeptical of anything referencing your booking history for longer than this week’s news cycle lasts.


Details current as of September 5, 2026, based on reporting from BleepingComputer and Infosecurity Magazine. This is an active, developing incident — verify current guidance directly with MAG or the National Cyber Security Centre if you believe you’re affected.