Forgotten Dairies

Britain’s Airports Secured Flights, But Betrayed Passenger Data -By Fransiscus Nanga Roka

MAG to enable oversight of retention practices and vendors should be investigated by the Information Commissioner’s Office; superfluous API secrets should be managed by standards dropped through the aviation sector by the National Cyber Security Centre under aviation-wide exfiltration detection criteria. Policymakers should mandate that critical-infrastructure operators report ransom demands and outlaw covert payment.

Published

on

Praise Manchester Airports Group for refusing to pay cyber extortionists This glaring lapse in protecting the personal data of 8.7 million clients calls for accountability.

On August 2026, a hacker accessed an unprotected database hosted by a third-party covering Manchester, London Stansted and East Midlands airports. The compromised records were related to airport Wi-Fi registrations, parking bookings, lounges and Fast Track services. MAG said the exposure of email addresses, telephone numbers, postcodes and vehicle-registration numbers had been confirmed but that no bank or payment information was held on the compromised system. The planes were flying, the passengers were safe and aviation-security systems worked.

However, “no operational disruption” does not equal no public harm.

It was claimed by FulcrumSec, a newer player in the data-extortion business. Its so-called “steal and squeeze” model ditches traditional data encryption used by ransomware: expropriate the information, kick up a ransom payment and then publish it when the target declines. The US group says MAG refused its requests and that customer data was released on the internet shortly after September 2. Related: Have I Been Pwned goes on to index 8.7 million impacted accounts

The who, what, when and where are becoming clearer. But the crucial “how” is a matter of debate.

Advertisement

According to FulcrumSec, its exploitation of credentials for the Iterable marketing platform that were hard-coded into publicly accessible JavaScript on airport sites. The attackers said this unmasked some 86GB of squeezed data, claimed to grow to around 550GB containing 108,077 individual vehicle registrations and almost 200,000 travel records set for the future.

Such details should as yet not be seen as established fact. MAG has not announced the API-key mechanism, nor archive size or future-itinerary claim; no regulator has made any technical finding. But an explicit cybersecurity assessment cautions that these numbers are largely from the extortionist and have not been independently verified.

Hackers are not neutral forensic auditors; they are criminals. These revelations are conclusive evidence of access, shaming victims and advertising their extortion brand in one fell swoop.

And yet, if privileged API keys were exposed in code delivered by a browser, that would be the perfect storm of stupidity, millions of records potentially accessible because someone took the view that a public interface is a private store. Complexity should not be the reason. Governance would.

No Card Numbers: Why Is The Breach Still A Threat? Because identity data becomes destructive power when matched. The criminal who knows an individual’s airport, phone number, postcode, car and booking history can gain a receipt for convincing parking fines, flight cancellations, refund requests or alerts to lounge payments. Generative AI is able to combine millions of fragmented records to generate personalized fraud at industrial scale.

Advertisement

There is no erasing the antecedent question, whatever MAG’s principled refusal (backed by appropriate law) to uphold: why was so much customer information retained, pooled and made accessible across a marketing ecosystem? Security, data minimization, purpose limitation and storage limitation are not just corporate aspirations under the UK GDPR; they are legal duties.

MAG must issue an independently audited incident report validating the entry point, timeline, affected processors, retention periods and specific data fields. It should take responsibility for financing fraud detection, hotlines for dedicated victims and the immediacy of corrections to false accounts opened through stolen identity.

Going through that in technical terms, you should revoke every single credential that has been exposed; secrets moved server-side, access tokens made finer grained and rotated frequently, bulk exports rate limited on both sides as well as third party platforms behind zero-trust controls. Delete any historical Wi-Fi and booking data that is no longer required.

MAG to enable oversight of retention practices and vendors should be investigated by the Information Commissioner’s Office; superfluous API secrets should be managed by standards dropped through the aviation sector by the National Cyber Security Centre under aviation-wide exfiltration detection criteria. Policymakers should mandate that critical-infrastructure operators report ransom demands and outlaw covert payment.

MAG was right not to give FulcrumSec a reward. Moral courage after a breach is not a replacement for competence before it. The company safeguarded its cash, it must now answer for not preserving everybody else’s ID.

Advertisement

Fransiscus Nanga Roka

Faculty of Law University 17 August 1945 Surabaya and Managing Partner Law Firm Victorious Indonesia

Leave a Reply

Your email address will not be published. Required fields are marked *

Exit mobile version