API leak exposes Manchester Airport Group to 86 GB data theft

An extortion gang is claiming it made off with 86 GB of data from Manchester Airports Group (MAG) after discovering API credentials embedded in client-side JavaScript—code that runs in every visitor’s browser. MAG confirmed a breach on August 27 but described a much smaller exposure, affecting email addresses, phone numbers, vehicle registrations and postcodes linked to 8.7 million customers. FulcrumSec now alleges the haul includes booking histories, marketing files and nearly 200,000 upcoming travel records through 2026, complete with dates, times and payment details.
A simple mistake, a major breach
According to the extortion group, the intrusion began when it inspected MAG’s websites and found airport-specific Iterable API keys left in the JavaScript delivered to users. Developer tools in any browser could have revealed the same credentials, giving attackers a direct route into backend systems without phishing, malware or zero-day exploits. FulcrumSec shared a 21.5 GB sample with BleepingComputer that matched real passenger details, including Fast Track bookings, terminal numbers and payment amounts. The group says it plans to publish both the stolen data and a technical breakdown, although it may redact upcoming travel records to limit immediate harm.
MAG has not addressed the 86 GB figure or the exposed-credentials claim directly. A spokesperson reiterated that “we have taken effective measures to protect our customers” and that affected customers with upcoming bookings have already been contacted. BleepingComputer notes it could not independently verify the full scope of the theft.
Why it matters
If confirmed, the incident shows how even basic coding oversights can have outsized consequences. Customer-facing websites must treat API keys and other secrets as sensitive material, regardless of where they are served. For travelers, the leak underscores the risk of combining identifiers like postcodes and vehicle registrations with travel details—information that can fuel highly targeted phishing campaigns. UK regulators and CISOs will likely revisit how client-side code is audited and how breach disclosures balance transparency with real-time customer notification.
Source: Security Affairs. AI-assisted editorial synthesis — TechnoExpress.

