What happened (in plain English)

Okay, grab a cuppa — apparently an extortion group calling itself FulcrumSec says it swiped about 86 GB of customer data from Manchester Airports Group. The crew claims the haul includes a big consolidated customer export and a load of booking and travel details tied to Manchester, London Stansted and East Midlands operations.

According to the group’s account, they slipped in using airport-specific API credentials that were accidentally exposed in client-side JavaScript. The samples the group shared reportedly contained lots of purchase history, booking references, terminal and product choices, dates and times — even device and IP info. They also claim the dataset includes nearly 200,000 records for people with upcoming travel plans later in 2026.

Before you panic: independent verification of the full claim and the entire dataset size hasn’t been possible, and the actor says it may publish or redact parts depending on concerns about real-world harm. The attackers reportedly asked for a ransom, which the operator is understood to have refused. The airport group has said it’s contacted people with upcoming bookings and offered support, and that airport operations and passenger safety were not affected.

What was exposed, why it matters, and what you should do

Sampled records — if genuine — go beyond names and emails. Expect things like:

  • contact details (emails, phone numbers)
  • vehicle registrations and parking bookings
  • booking references, product selections, prices and discounts
  • dates, times and terminal information for travel
  • historical spending, device and IP details, and marketing classifications

Reviewers did not find obvious payment-card or bank account data in the samples — so no payment-card evidence was observed — but the other details are juicy enough for convincing phishing or scam messages. A full UK postcode can narrow down addresses to a very small group, and paired with travel and vehicle info it makes impersonation scams much easier to pull off.

Practical steps if you might be affected:

  • Be skeptical of unexpected calls, texts, or emails about bookings — don’t give out payment details over the phone.
  • Verify any message by going directly to the airport or booking provider’s official website or phone number.
  • Watch for phishing that references specific travel dates, parking details, or booking references — these are classic lures now.
  • Consider changing reused passwords and enable multi-factor authentication where possible.
  • Monitor your accounts and set up alerts for unusual activity; consider credit/fraud monitoring if you’re concerned.

Short version: the claim is serious and unpleasant, but not the end of the world. Keep your wits, double-check anything that asks for money or sensitive info, and assume scammers will try to sound very convincing.