HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Manchester Airports Group Data Breach Exposes 8.8 Million Passengers via Hard‑Coded Admin Keys

Manchester Airports Group confirmed a breach that leaked personal data of 8.8 million passengers after admin keys were discovered in the client‑side JavaScript of its three airport websites. The exposure highlights the need for continuous secret‑management controls to satisfy audit and regulatory expectations.

Verisq™ Intelligence · 📅 September 05, 2026 · 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

Crooks Behind Manchester Airports Group Hack Leaks Data of 8.8 Million People

What Happened – Attackers claiming to be the extortion group FulcrumSec released a half‑terabyte dump containing email addresses, phone numbers, vehicle registrations and postcodes for 8.8 million passengers of Manchester, London Stansted and East Midlands airports. The breach originated from administrator keys that were hard‑coded in the client‑side JavaScript of each airport’s public website, giving the attackers unrestricted read access to a third‑party booking database.

Why It Matters for Trust & Control Assurance

  • This incident is a textbook example of a secret‑management failure that a continuous control‑assurance program must detect, document and remediate.
  • Demonstrating that secrets are never exposed in client‑side code, and that key rotation and access reviews are continuously monitored, provides the audit‑ready evidence required by multiple frameworks.
  • Verisq’s Control Mapping capability can automatically surface such configuration gaps across your web assets and supply the defensible evidence needed for regulators and auditors.

Who Is Affected – Aviation operators, airport‑service vendors, travel‑booking platforms, and any organization that stores passenger PII in web‑exposed services.

Recommended Actions

  • Conduct an immediate secret‑scanning of all public‑facing code repositories and web assets.
  • Rotate any exposed keys, enforce least‑privilege API access, and implement automated alerts for future secret leaks.
  • Update third‑party risk assessments to include secret‑management controls and collect evidence for audit readiness.

Technical Notes – The attackers leveraged hard‑coded admin API keys embedded in JavaScript (a classic client‑side secret exposure). No payment‑card data were taken, but the combination of PII and vehicle details creates a high fraud risk. Source: SecurityAffairs

📰 Original Source
https://securityaffairs.com/198447/data-breach/crooks-behind-manchester-airports-group-hack-leaked-data-of-8-8-million-people.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →