Manchester Airports Group's data was taken using Iterable API keys exposed in the airports' front-end JavaScript
Assessment
ThreatPaper checked the attacker's claim against Internet Archive copies of the _app JavaScript bundle each airport site served. Manchester's bundles archived on 15, 19 and 22 August 2026 contain a site-configuration object with a populated 32-character IterableApi.Key and the URL api.iterable.com; East Midlands' bundle of 16 August carries a different populated key; Stansted's bundle of 26 August and every bundle served since have the field empty. MAG has not confirmed the mechanism and Iterable has not commented, but the credential was where the group said it was. The key values are not reproduced
Where this claim appeared
FulcrumSec via BleepingComputer · 2026-08-27
https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/What “Verified” means
Established by primary sources — the original disclosure, a vendor incident report, a court filing, a government advisory, or the affected party itself. Where a claim is material, at least two independent sources agree.
5 of 5 · rating scale
Assessed in
Manchester Airports Group Breach: The Iterable Key in the Front-End JavaScript Since 2023Think this assessment is wrong? Report an error.