ThreatPaper
Weak Evidence

Hackers breached Manchester Airports Group's systems

Assessment

The data lived in Iterable, a third-party marketing platform, and was retrieved with MAG's own API credential exposed in MAG's websites. No MAG server, network or internal system is reported compromised, and MAG's statement refers with some care to "the system accessed" rather than to its own systems. The credential exposure was MAG's failure and the data was MAG's data, so the breach is MAG's in every sense that matters to the 8.8 million people affected; the description of it as a hack of MAG's systems is not what happened.

Where this claim appeared

Cybernews · 2026-09-11

https://cybernews.com/security/hackers-publish-sensitive-data-of-nearly-9m-uk-travelers-manchester-airports/

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

Manchester Airports Group Breach: The Iterable Key in the Front-End JavaScript Since 2023

Think this assessment is wrong? Report an error.