Hackers have made public the personal information of nearly 9 million individuals online after an extortion attempt against Manchester Airports Group (MAG) failed. The group responsible, called FulcrumSec, had threatened to release the data unless MAG paid them a ransom. When MAG refused to pay, the hackers posted the database on the dark web, a part of the internet that requires special software to access and is often used for illicit activities.
The database includes personal information collected from individuals who used services at MAG airports, such as WiFi, parking, lounges, or other related services. While the exact details of the data are not fully known, most of the records appear to be email addresses collected when users signed up for airport WiFi. A smaller portion of the data includes phone numbers, vehicle registration numbers, and postal codes from customers who made parking or lounge reservations. Importantly, no financial details like payment information, passwords, or passport data were included in the leak.
Cybersecurity experts have raised concerns about the risks associated with the release of this data. They warn that the information could be used for phishing attacks or other fraudulent activities. They advise individuals affected by the breach to take precautions, such as using unique passwords, being cautious of suspicious emails, and regularly checking their credit reports for any unusual activity.
The breach occurred after hackers gained access to an internal system at MAG, allowing them to steal data from a third-party database. It is still unclear whether the data was taken directly from the third-party system or through MAG’s network. This uncertainty may affect how the failure in security measures is understood and addressed.
The UK’s Civil Aviation Authority has established a Cyber Assessment Framework for Aviation, developed in collaboration with the National Cyber Security Centre. This framework requires a strict separation between IT systems and operational technology to ensure that critical systems, such as those controlling flight operations or baggage handling, are not compromised. It is not clear whether MAG was following this framework at the time of the incident. However, the breach appears to have affected data systems rather than the systems that keep planes running, meaning that flight operations, baggage handling, and terminal systems were not impacted. Experts suggest that this incident could serve as a cautionary example for other organizations and emphasize the need for stronger cybersecurity measures and consumer awareness to prevent future exploitation of such data.
Manchester Airports Group Data Breach Exposes 8.7 Million Records, Prompting Concerns Over Cybersecurity Practices
AI-rewritten from original reportingHow it works
cyberattackdata-leakhackersmanchester-airportsphishingsecurity



