The hacking group FulcrumSec announced it stole approximately 86 gigabytes of data from Manchester Airports Group in a cyberattack disclosed on August 30, 2026. The claim was made directly to BleepingComputer, which reviewed sample files provided by the attackers. The data allegedly includes internal information consistent with the airports group’s operations. Manchester Airports Group manages major UK airports including Manchester, London Stansted, and East Midlands.
FulcrumSec, known for extortion tactics, stated the breach resulted from exploiting vulnerabilities in the organization’s network defenses. The group did not disclose the exact method used but indicated access was gained through compromised credentials. BleepingComputer verified the authenticity of the data samples, confirming they contained employee details, internal communications, and operational documents. The attackers threatened to release the full dataset unless a ransom demand was met, though no payment has been confirmed.
The stolen data reportedly includes staff personal information, internal emails, flight operational logs, and security protocol documents. Samples showed names, job titles, email addresses, and shift schedules for airport personnel. Some files contained details about baggage handling systems and access control logs. FulcrumSec emphasized the sensitivity of the material, suggesting it could be used for targeted phishing or social engineering attacks against employees. The group claimed the data spans multiple years of internal records.
Manchester Airports Group has not publicly confirmed the breach but acknowledged it is investigating a potential cybersecurity incident. The organization stated it has engaged external forensic experts and notified relevant UK authorities, including the Information Commissioner’s Office. The airports group emphasized its commitment to protecting customer and employee data while working to restore full system integrity.
Was customer data stolen in the Manchester Airports breach? FulcrumSec did not claim to have taken customer databases or payment information in their statement to BleepingComputer. The leaked samples focused on internal employee and operational records.
Has Manchester Airports Group confirmed the attack? The organization has not issued a public confirmation but confirmed it is investigating a cybersecurity incident and has taken precautionary measures.
What should employees do following the breach? Staff are advised to remain vigilant against phishing attempts, update passwords, and report any suspicious communications to internal security teams.