ThreatPaper
Verified

Manchester Airports Group's data was taken using Iterable API keys exposed in the airports' front-end JavaScript

Assessment

ThreatPaper checked the attacker's claim against Internet Archive copies of the _app JavaScript bundle each airport site served. Manchester's bundles archived on 15, 19 and 22 August 2026 contain a site-configuration object with a populated 32-character IterableApi.Key and the URL api.iterable.com; East Midlands' bundle of 16 August carries a different populated key; Stansted's bundle of 26 August and every bundle served since have the field empty. MAG has not confirmed the mechanism and Iterable has not commented, but the credential was where the group said it was. The key values are not reproduced

Where this claim appeared

FulcrumSec via BleepingComputer · 2026-08-27

https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/

What “Verified” means

Established by primary sources — the original disclosure, a vendor incident report, a court filing, a government advisory, or the affected party itself. Where a claim is material, at least two independent sources agree.

5 of 5 · rating scale

Assessed in

Manchester Airports Group Breach: The Iterable Key in the Front-End JavaScript Since 2023

Think this assessment is wrong? Report an error.