Hackers Dump 8.7 Million Airport Customers' Data on the Open Internet
Want more insights like this?
8.7 million people are at risk after hackers breached Manchester Airports Group (MAG) — operator of Manchester, Stansted, and East Midlands airports — and published the stolen data for free. FulcrumSec extorted MAG for an undisclosed sum, failed to get paid, and dumped half a terabyte in response: "every byte of it is pure PII," the gang wrote.
HaveIBeenPwned indexed the dump within a day — names, emails, phone numbers, IP addresses, and 108,000 vehicle plates among them. Unlike most leak sites, this one sits on the open internet rather than the dark web, so anyone can reach it.
Security researcher Kevin Beaumont warned that wealthy or high-profile people face particular risk: the files map where customers have been and where they're going next, including some 190,000 upcoming bookings. MAG says it contacted those travelers separately. Everyone else should expect scammers who know their phone number and car registration.
FulcrumSec says it got in the same way it hit Arup and Novo Nordisk: admin keys to Iterable, MAG's marketing platform, left in the airport websites' JavaScript. "Any of the millions of visitors to the site could have right-clicked 'inspect' and seen the keys," the gang wrote. MAG hasn't confirmed it.
Source: BBC News