FulcrumSec has claimed responsibility for the Manchester Airports Group breach and told BleepingComputer it stole about 86 GB of data from the United Kingdom airport operator. The report remains partly unverified: BleepingComputer says it reviewed samples and validated one traveller’s record, but could not independently confirm the full size of the dataset, the alleged access route, or the scope of the threat actor’s access. Manchester Airports Group, or MAG, disclosed on August 27 that an unauthorized third party had stolen customer data tied to Manchester, London Stansted, and East Midlands airports, according to BleepingComputer. MAG said the affected information came from car park, lounge, and Fast Track bookings, as well as in-airport Wi-Fi registrations. BleepingComputer reports that FulcrumSec contacted the outlet by email and shared samples as evidence. The outlet said one record matched a traveller’s known Manchester Airport purchase history, including prior Fast Track purchases, booking and scheduled-arrival times, the terminal used, amounts paid, purchase references, total spending, and the apparent purpose of trips. The samples also suggested a broader set of details than MAG initially disclosed, according to BleepingComputer. The outlet said the material included a roughly 21.5 GB Manchester customer export containing consolidated profiles that combined customer identifiers with historical booking activity and marketing classifications. FulcrumSec further claimed it gained access through airport-specific Iterable application programming interface credentials exposed in client-side JavaScript. It also claimed the stolen material includes nearly 200,000 records related to upcoming travel during the rest of 2026, allegedly linking dates, times, and booking information with personally identifiable information. BleepingComputer said it could not independently verify those claims. The group told BleepingComputer it intends to publish the stolen data and a technical account of the intrusion, while also saying it may withhold or redact the upcoming-travel records because of potential real-world harm. BleepingComputer said it deleted the supplied material after its review and would not publish or share it. BleepingComputer identifies FulcrumSec as a financially motivated data-extortion group active since 2025, focused on stealing sensitive corporate information and threatening publication rather than encrypting victim systems. The group has previously claimed attacks on organizations including LexisNexis, Novo Nordisk, Global Schools Group, and Avnet, according to the report. MAG did not address BleepingComputer’s specific questions about the claimed 86 GB dataset, exposed credentials, or future-travel data. A spokesperson instead referred the outlet to an updated statement saying affected customers with upcoming bookings had been contacted. Who benefits: FulcrumSec benefits from publicizing the claim because data-extortion groups use disclosure pressure as leverage. Security teams also get a concrete control to examine: whether API credentials are exposed in client-side code. Who's exposed: MAG customers who used car park, lounge, Fast Track, or in-airport Wi-Fi services are the population MAG has described as affected. Customers with upcoming bookings warrant particular caution, though the nearly 200,000-record figure remains unverified.