A significant data breach has affected the Manchester Airports Group (MAG), compromising the personal information of 8.8 million individuals. The breach involved the exposure of email addresses, phone numbers, vehicle registrations, and postcodes. The incident was disclosed by MAG last week, revealing that hackers had infiltrated its systems and stolen data related to car park, lounge, and Fast Track bookings as well as in-airport Wi-Fi sign-ups across its Manchester, London Stansted, and East Midlands locations. Importantly, the breach did not disrupt the airport's operations.

The stolen data was stored in a database managed by a third-party provider. MAG received a ransom demand from the attackers, identified as the FulcrumSec extortion group, who later published approximately 550 gigabytes of uncompressed data online. The leaked information includes the names, emails, phone numbers, town and postal region, and residential IP addresses of individuals who accessed MAG's services. The dataset also contains details of over 2.4 million purchases, hundreds of thousands of booking-related SMS messages, and unique UK vehicle registration plates.

FulcrumSec alleges that they accessed MAG's systems using admin keys found within the frontend JavaScript of the airport websites. Although MAG did not comply with the ransom demand, the attackers have publicly released the data. The breach has been verified by the data breach notification service, HaveIBeenPwned, which has added the compromised data to its database. Security teams are advised to be vigilant and take immediate steps to mitigate potential risks stemming from this breach.