ThreatPaper
Data BreachExtortion & BlackmailHigh

Manchester Airports Group Breach: The Iterable Key in the Front-End JavaScript Since 2023

By Sethu Satheesh · 13 Sept 2026 · 14 min read

Threat Actor: FulcrumSec (self-claimed extortion group; prior claimed victims LexisNexis, Novo Nordisk, Avnet) · Target: Manchester Airports Group — customers of Manchester, London Stansted and East Midlands airports' car-park, lounge, Fast Track and Wi-Fi services; ~8.8 million people

Source: www.manchesterairport.co.uk


Executive Summary

On 27 August 2026 Manchester Airports Group, operator of Manchester, London Stansted and East Midlands airports, disclosed that "an unauthorised third party" had obtained "a quantity of customer data" relating to "car park, lounge and Fast Track bookings and in-airport WIFI sign-ups" across all three airports. MAG said the data included "email addresses, phone numbers, vehicle registrations and postcodes," that neither MAG nor "the system accessed" held payment details, that operations were unaffected, and that "at no point has passenger safety or aviation security been compromised." A group calling itself FulcrumSec claimed the intrusion, demanded a ransom MAG has confirmed receiving and refused, and on the weekend of 30–31 August published roughly 550 GB of uncompressed data. Have I Been Pwned loaded it on 2 September: 8.8 million email addresses, with names, phone numbers, IP addresses, user-agent strings, locations, purchases and vehicle registration plates.

The mechanism, as FulcrumSec described it and as this paper has verified, was not an intrusion into MAG at all. The three airport websites are Next.js applications that embed a site configuration object in their client-side bundle, and that object included an API key for Iterable, the customer-engagement platform MAG uses for marketing email and SMS. "These keys were not found on some obscure subdomain," the group said. "All three of these were on the sites' root domain." ThreatPaper retrieved the Internet Archive's copies of the _app bundle served by manchesterairport.co.uk and found "IterableApi":{"Key":"…","Url":"https://api.iterable.com"} with a 32-character key in the bundles archived on 15, 19 and 22 August 2026, and the identical key, by hash, in every archived build back to 1 January 2023. East Midlands' bundle of 16 August carries a different key. Stansted's bundle archived on 26 August, the day before MAG's disclosure, already has the key field empty; so does every bundle served since. The key had been public for at least three years and eight months. It is not reproduced here.

What a key like that can do depends on its type. Iterable issues Web keys, limited to a handful of client-side endpoints, and Standard and Server-side keys with access to the export and user-lookup APIs; its documentation says the latter "should not be used in client-side code." The volume FulcrumSec published, 8.7 million profiles, 1.2 billion marketing events, 2.5 million purchase records, 461,000 SMS messages and 191,000 bookings for future travel, is only reachable through the export endpoints. The group's word for the keys was "admin." MAG has not said which type they were, and Iterable has not commented.

Neither has the Information Commissioner's Office. MAG says it has "informed and are working with the relevant authorities" and has "contacted affected customers directly"; it has not published a count, named the platform, or said how long the key was exposed. The data that was published is precisely the kind that enables the next fraud: who parks at which airport on which dates, their car, their phone, and the text messages MAG sent them. Nearly 200,000 of the records describe travel that has not happened yet.

Verification of Claims

  1. Claim: MAG disclosed a breach affecting car park, lounge, Fast Track and Wi-Fi customers at all three airports on 27 August 2026. → Verified → MAG incident page, dated 27.08.26.

  2. Claim: 8.8 million people are affected. → Verified as HIBP's count → Have I Been Pwned, added 2 September 2026: 8,800,000 accounts. FulcrumSec: ~8.7 million profiles. MAG has published no number.

  3. Claim: Access was through Iterable API keys in the airports' front-end JavaScript. → Verified → FulcrumSec's claim, confirmed by ThreatPaper against Internet Archive copies of the _app JavaScript bundles of all three sites: a populated IterableApi.Key in Manchester's bundles archived 15, 19 and 22 August 2026 and East Midlands' of 16 August; the field empty in Stansted's of 26 August and in all bundles served since.

  4. Claim: The key had been exposed since at least January 2023. → Verified → The SHA-256 of the Manchester key in the 22 August 2026 bundle matches the key in archived bundles of 1 January 2023, 8 March 2023 and every subsequent archived build examined. Whether the key was live in Iterable throughout is MAG's to say.

  5. Claim: The keys were admin keys. → Assessed, not confirmed → FulcrumSec's word. The key value does not reveal its type. The published data set is consistent only with a key holding export permissions, which Iterable's Web key type does not have.

  6. Claim: MAG refused to pay a ransom. → Verified → SecurityWeek: MAG "confirmed receiving a ransom demand"; FulcrumSec: "MAG did not pay a ransom." Amount not disclosed.

  7. Claim: 550 GB of data was published. → Verified as reported → SecurityWeek: ~550 GB uncompressed; Infosecurity: ~549 GB; BleepingComputer, 3 September: ~640 GB uncompressed from 86 GB compressed. The figures describe the same release at different points of measurement.

  8. Claim: No payment card data was taken. → Verified as MAG's statement → "Neither MAG nor the system accessed hold customers' bank or payment details." BleepingComputer's review of samples found none.

  9. Claim: MAG's systems were breached. → False as phrased → The data was in Iterable's platform, retrieved with MAG's own credential. MAG's statement is careful on this: "the system accessed." No MAG server is reported compromised.

  10. Claim: FulcrumSec removed the most sensitive data before publishing. → Unverified → The group's own statement. HIBP's data classes and the published event, SMS and future-booking counts suggest little was withheld.

Timeline

Date Actor Event Source
≤ 1 January 2023 MAG Manchester Airport's Next.js bundle ships an Iterable API key in its site configuration. Same key persists in every archived build thereafter. Internet Archive, verified by ThreatPaper
15–22 August 2026 MAG Bundles served carry the key; East Midlands' bundle (16 Aug) carries a different populated key. Internet Archive
August 2026 FulcrumSec Retrieves data from MAG's Iterable project using the exposed credentials. FulcrumSec via BleepingComputer
≤ 26 August 2026 MAG Stansted's bundle archived with IterableApi.Key empty; containment under way before disclosure. Internet Archive
27 August 2026 MAG Public disclosure and FAQ; customers contacted; "relevant authorities" informed. MAG
27 August 2026 FulcrumSec Claims the breach to BleepingComputer: 86 GB compressed; Iterable keys in client-side JavaScript. BleepingComputer
Late August 2026 FulcrumSec; MAG Ransom demanded; MAG declines. SecurityWeek
30–31 August 2026 FulcrumSec ~550 GB published. SecurityWeek; Infosecurity
2 September 2026 HIBP Breach loaded: 8.8M accounts. HIBP
3 September 2026 BleepingComputer Update: ~640 GB uncompressed; ~191,000 future-travel records. BleepingComputer
7 September 2026 MAG Manchester's served bundle has an empty key field. Internet Archive
13 September 2026 ThreatPaper All three sites' live bundles: "IterableApi":{"Key":""…}. Direct observation

Attack Anatomy

Loading diagram...

Stage 1: reading the page

No exploitation was required. MAG's airport sites are built on Next.js, which serializes application configuration into a JavaScript bundle every visitor downloads. The bundle in question, /_next/static/chunks/pages/_app-*.js, contains a configuration object with the sites' API endpoints, tracking IDs and, alongside them, the Iterable key and base URL. Anyone opening browser developer tools, or fetching the file with curl, had it. So did the Internet Archive, which is how this paper checked the claim without touching MAG's systems.

Stage 2: the key's reach

Iterable is the platform behind MAG's marketing email and SMS, which is why the published data includes 461,000 SMS messages and 1.2 billion "marketing events": every open, click, send and page view the platform tracked. Its API exposes user profiles, event history and bulk export. Iterable's documentation distinguishes key types by environment and warns that server-side keys "should not be used in client-side (web, mobile, or otherwise) code." A Web key can post events and update a user; it cannot export a project. The scale of what was taken settles which kind this was, whatever it was labelled.

Stage 3: exfiltration

FulcrumSec's initial claim was 86 GB compressed. The published set decompressed to roughly 550–640 GB: ~8.7 million profiles with names, emails, phone numbers, postcodes and residential IP addresses; ~2.5 million purchase records; 108,000 vehicle registration plates; ~191,000 records of future bookings with dates and times. Iterable's export API is designed to deliver exactly this, in bulk, to an authenticated caller. There is no reason to think the platform saw anything unusual.

Stage 4: extortion and publication

The group demanded payment, MAG refused, and the data went up within four days of disclosure. FulcrumSec says it withheld "the most sensitive parts." The group's previous claimed victims, LexisNexis, Novo Nordisk, Global Schools Group and Avnet, fit a pattern of finding credentials in public-facing infrastructure rather than breaking in; Cybernews on 11 September described the group as continuing "to find hardcoded credentials in public-facing IT infrastructure."

What the archive shows

Manchester's key was present, unchanged, in archived bundles from 1 January 2023 to 22 August 2026. Stansted's field was empty in a bundle archived on 26 August; MAG disclosed on 27 August. The sequence is consistent with MAG rotating or revoking the keys as its first containment step, before going public. The field itself is still in the bundle, empty, on all three sites today, which suggests the code path that reads it still exists and the value has been moved elsewhere.

Threat Actor Profile

  • Name / Alias: FulcrumSec. No government or vendor attribution.
  • Motivation: Extortion by data theft and publication.
  • Method signature: Credentials exposed in public-facing web assets, used against the SaaS platforms they unlock. No malware, no exploit, no lateral movement inside the victim.
  • Prior claims: LexisNexis, Novo Nordisk, Global Schools Group, Avnet (BleepingComputer); pattern described by Cybernews as recurring hardcoded-credential discovery.
  • Behaviour in this case: Claimed to press within hours of MAG's disclosure; published within four days; asserted partial redaction of published data.
  • MITRE ATT&CK techniques (verified on attack.mitre.org, 13 September 2026):
    • T1594 Search Victim-Owned Websites
    • T1552.001 Unsecured Credentials: Credentials In Files (client-side bundle)
    • T1078.004 Valid Accounts: Cloud Accounts (Iterable project)
    • T1530 Data from Cloud Storage; T1213 Data from Information Repositories
    • T1567 Exfiltration Over Web Service (Iterable export API)
    • T1657 Financial Theft (extortion)

Technical Indicators

# No attacker infrastructure has been published. The indicator in this case
# is the victim's own configuration. Key values are deliberately omitted.
exposed_secret:
  location: /_next/static/chunks/pages/_app-<hash>.js on each airport root domain
  shape: '"IterableApi":{"Key":"<32 chars>","Url":"https://api.iterable.com"}'
  sites: [manchesterairport.co.uk, stanstedairport.com, eastmidlandsairport.com]
  manchester_key_present: archived builds 2023-01-01 → 2026-08-22 (same value)
  east_midlands_key_present: archived build 2026-08-16 (different value)
  stansted_key_empty: archived build 2026-08-26
  all_sites_key_empty: live bundles 2026-09-13
platform: Iterable (customer engagement); export API
published_data (HIBP, 2026-09-02):
  accounts: 8,800,000
  classes: [names, emails, phone numbers, IP addresses, user agents, geographic locations, purchases, vehicle registration plates]
volume: 86 GB compressed; ~550–640 GB uncompressed
ip_addresses: []
domains: []
file_hashes: []

UK GDPR. MAG is the controller; Iterable is a processor. A breach of this size requires notification to the Information Commissioner's Office within 72 hours of awareness and, given the risk to individuals, notification to data subjects. MAG says it has "informed and are working with the relevant authorities" and has "contacted affected customers directly." The ICO has made no public statement as of 13 September. The exposure of a processor credential in the controller's own website for more than three years bears directly on the Article 32 security obligation.

Notification content. MAG's public statement lists four data fields. The published data set, per HIBP and the group's own inventory, includes names, residential IP addresses, user-agent strings, purchase histories, SMS content and future travel dates. MAG has not updated its page since 27 August.

Ransom. MAG confirmed a demand and declined it. No UK law prohibits payment; the National Cyber Security Centre and ICO jointly discourage it.

Aviation regulation. MAG's statement that "aviation security" was not compromised is accurate: no operational or security system is involved. The Civil Aviation Authority has no reported role.

Vendor. Iterable has not commented. Its documentation places responsibility for key type and placement on the customer.

Litigation. None reported. UK group actions for data breaches face the Lloyd v Google threshold; individual claims for distress are possible.

Impact Assessment

  • Individuals affectedConfirmed by third-party load. 8.8 million email addresses (HIBP).
  • Data classesConfirmed. HIBP: names, emails, phones, IPs, user agents, locations, purchases, plates. MAG's statement lists four of these.
  • VolumeReported. ~550–640 GB.
  • Future travel exposedReported. ~191,000 bookings through end of 2026 (FulcrumSec via BleepingComputer).
  • SMS contentReported. ~461,000 messages.
  • Payment dataNot taken, per MAG and sample review.
  • Duration of key exposureVerified. ≥ 3 years 8 months (Manchester).
  • MAG systems compromisedNo. Third-party platform, first-party credential.
  • Operational impactNone.
  • Ransom paidNo.

Lessons and Defensive Recommendations

For anyone who books MAG parking or lounges

  • Assume your name, phone, email, postcode, car registration and travel dates are in circulation. Expect phishing that knows your booking. MAG will not call for card details; nobody legitimate will.
  • If you have a future booking in the published set, the date you are away from home is known. That is a burglary risk, not just a phishing one.

For web engineering teams

  • Grep your production bundles for API keys today: curl the _app chunk and search for Key, token, api. Next.js, Nuxt and every framework that serializes config to the client will ship whatever you put in it.
  • A third-party key in client code should be a client-type key. Iterable, like most SaaS, issues them; they cannot export your user base.
  • Rotate on a schedule. A key that has not changed since 2023 is a key you have lost track of.
  • Assume the Internet Archive has your old bundles. Rotating the key in the current build does nothing about copies of the previous one.

For MAG

  • The statement lists four data fields; the published data has a dozen. Customers are being notified of less than was taken.
  • "The system accessed" was a marketing platform holding three years of behavioural data on 8.8 million people. The retention question is the same one IDScan and Thomson Reuters faced this month.

For security teams generally

  • FulcrumSec's method is one view-source. The breach surface here was the vendor relationship and the secret that made it work. Audit every SaaS credential your web properties carry, and which of them can read as well as write.

Sources

  1. Manchester Airports Group. "Data Security Incident – 27.08.26: Statement and updates". 27 August 2026.
  2. Have I Been Pwned. "Manchester Airports Group". Added 2 September 2026.
  3. BleepingComputer. "FulcrumSec claims Manchester Airports hack, theft of 86 GB of data". 27 August 2026, updated 3 September.
  4. SecurityWeek. "Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal". 3 September 2026.
  5. Infosecurity Magazine. "FulcrumSec Claims Responsibility for Manchester Airport Group Breach". September 2026.
  6. Internet Archive. Manchester Airport _app bundle, snapshot of 22 August 2026; homepage snapshots of 15 August and 7 September 2026. East Midlands and Stansted bundles of 16 and 26 August 2026. Key values redacted in this paper.
  7. Iterable Support Center. "API Keys"; "Getting Started with Iterable's API".
  8. Cybernews. "UK airport data breach: hackers publish nearly 9M traveler records". September 2026.
  9. MITRE ATT&CK. T1552.001; T1594; T1078.004. Accessed 13 September 2026.
Original Incident Report →

Related Research

Cl0p exploited an unauthenticated deserialization flaw in PTC Windchill as a zero-day in June 2026, deployed a purpose-built web shell that decrypts the application's keystore, and named 43 manufacturers, including Shell, Philips and GE. It was the second such flaw in three months.

Extortion & BlackmailOT & Industrial SystemsData Breach

ShinyHunters says it vished McKesson employees, took over Okta sessions, and pulled a terabyte from Salesforce and Snowflake between 20 and 25 August 2026. McKesson has confirmed exfiltration of patient data and nothing about how.

Data BreachExtortion & BlackmailSocial Engineering

Three men who worked in incident response ran BlackCat attacks. One of them was simultaneously negotiating on behalf of ransomware victims — and passing the attackers his own clients' insurance limits.

RansomwareInsider ThreatExtortion & Blackmail