<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Hackers Dump 8.7 Million Airport Customers' Data on the Open Internet

Manchester Airports Group data including addresses, phone numbers, and license plates is now circulating publicly. Experts warn of follow-on scams.
Content Team

8.7 million people are at risk after hackers breached Manchester Airports Group (MAG) — operator of Manchester, Stansted, and East Midlands airports — and published the stolen data for free. FulcrumSec extorted MAG for an undisclosed sum, failed to get paid, and dumped half a terabyte in response: "every byte of it is pure PII," the gang wrote.

HaveIBeenPwned indexed the dump within a day — names, emails, phone numbers, IP addresses, and 108,000 vehicle plates among them. Unlike most leak sites, this one sits on the open internet rather than the dark web, so anyone can reach it.

Security researcher Kevin Beaumont warned that wealthy or high-profile people face particular risk: the files map where customers have been and where they're going next, including some 190,000 upcoming bookings. MAG says it contacted those travelers separately. Everyone else should expect scammers who know their phone number and car registration.

FulcrumSec says it got in the same way it hit Arup and Novo Nordisk: admin keys to Iterable, MAG's marketing platform, left in the airport websites' JavaScript. "Any of the millions of visitors to the site could have right-clicked 'inspect' and seen the keys," the gang wrote. MAG hasn't confirmed it.

Source: BBC News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo