// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
ColdRecon / Breach Radar / Manchester Airports Group
Breach Record

Manchester Airports Group

DISCLOSED 2026-09-01 · MISCONFIG · 8,700,000 RECORDS EXPOSED

Manchester Airports Group experienced a data breach exposing 8.7 million customer records. The extortion group FulcrumSec exploited an Iterable API key found in publicly accessible JavaScript, stealing 86 GB of data including 200,000 travel itineraries. No server intrusion was required.

The record

What we know

Disclosed
2026-09-01
Attack vector
Misconfig
Sector
aviation
Country
United Kingdom
Records exposed
8,700,000
Data classes exposed
customer recordstravel itineraries
ColdRecon assessment

Could a positive-security control have prevented this?

Verdict · would prevent · opinion

A positive-security model that prevents unauthorized access to exposed API keys and blocks data exfiltration from misconfigured public-facing assets would likely have prevented this breach, as the attack relied on a publicly exposed credential rather than endpoint compromise.

Our assessments are opinion, grounded in the cited public facts. Read them critically.

Sources

Cited reporting

Similar vector · recent

Other misconfig breaches on file

This page is the permanent ColdRecon entry for the Manchester Airports Group disclosure. It updates if new public reporting emerges. All tracked breaches →

Manchester Airports Group just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →