FulcrumSec Claims 80GB Manchester Airports Hack
FulcrumSec claims 80 GB of Manchester Airports Group data and threatens public release. No extortion group had claimed the breach when MAG disclosed it on August 28.

Extortion claim confirmed. SecurityWeek reports that FulcrumSec has claimed over 80 GB of data stolen from Manchester Airports Group (MAG) and plans to release it publicly.
What Changed Since August 28
Our initial coverage reported MAG confirming unauthorized access to Wi-Fi sign-up data affecting 8.7 million travelers across Manchester, Stansted, and East Midlands airports. At disclosure time: no threat actor had claimed credit, no extortion demand had surfaced publicly.
That changed August 31. FulcrumSec published a claim; SecurityWeek confirmed it.
Status as of September 1, 2026
- Breach: confirmed by MAG.
- Threat actor claiming credit: FulcrumSec.
- Volume claimed by FulcrumSec: over 80 GB.
- Volume confirmed by MAG: 8.7 million Wi-Fi sign-up records — scope of 80 GB claim not independently verified.
- MAG’s stated data type in scope: email addresses, “vast majority” of cases.
- FulcrumSec’s stated intent: public release.
Confidence Flags
FulcrumSec’s 80 GB figure: unconfirmed by MAG. The claim has not been independently verified beyond FulcrumSec’s own publication.
Whether FulcrumSec is responsible for the initial breach or is a secondary actor claiming access to data already circulating: not established.
MAG’s August 28 disclosure noted the investigation was ongoing. No updated MAG statement as of publication.
Context
FulcrumSec is not among the established high-volume ransomware operations. Attribution of the original intrusion to this group is unconfirmed.
MAG operates three UK airports serving more than 60 million passengers annually. The ICO referral filed at disclosure means a regulatory review is in progress; the extortion claim adds pressure to that timeline.
Analysis: the gap between breach disclosure and threat actor claim in this case was three days. Disclosure without attribution at Day 0 leaves organizations in a reactive position when a claim surfaces later.
McKesson is also facing an active extortion deadline this week from ShinyHunters. Berlin refused a Rhysida ransom demand last week.
Found this useful? Share it.


