Connect with us

Forgotten Dairies

No Ransom Paid, But Millions Still Pay -By Fransiscus Nanga Roka

Refusing payment denies criminals profit. The goal is to strip them of their power that comes with the breach being effective. The first was accomplished by MAG; the second, however, has flummoxed regulators.

Published

on

Manchester Airports Group does not pay cyber extortion. That was the correct decision. It does not turn MAG into a protagonist in a narrative where roughly 8.7 million customers also lost track of their data.

Discovered in late August 2026, the breach hit databases underpinning Manchester, London Stansted and East Midlands airports. This was linked to registrations and bookings at airports done via Wi Fi — and for parking, lounges and Fast Track services. MAG said that the email addresses, telephone numbers, postcodes and vehicle registrations were accessed. The bank and payment information was not stored on the purchased system, it said, as were aviation security operations, such as passenger safety and airport operation.

Those assurances cover what didn’t happen. They do not function as a counterbalance to what did.

After MAG refused the ransom demand, the extortion group FulcrumSec emerged and allegedly released data on 8.7 million individuals. That leak has also now been added to the Have I Been Pwned catalog of breaches, which lists names, contacts, IP addresses geolocation data, browser fingerprints and purchase and vehicle-registration numbers among the affected hit-by-breach categories.

How did the attackers enter? FulcrumSec said it discovered airport-specific credentials for the Iterable marketing platform which had been exposed in client-side JavaScript. It is also said to have retrieved around 86GB of compressed data and around 200,000 records relating to travel into the future.

Advertisement

These allegations are serious, but remain attacker claims rather than regulatory conclusions. Their public announcement does not state if the theory around the API-key is accurate, or if 86GB figure, and a 550GB extracted archive of an FSYX future-itinerary dataset. It has not yet been established what the technical cause was that led to the hours-long outage on December 13, or who would be legally responsible for it, with no public finding from Information Commissioner’s Office (ICO) yet made.

That matters because extortionists weaponize publicity as strategically as they weaponize the stolen data. Spread their marketing copy as forensic fact, not journalism scrutinising their evidence.

Even so MAG cannot hide behind uncertainty. Embedding a privileged API credential in publicly accessible code is not sophisticated intrusion, it is institutional negligence automated at scale. A secret stored in a browser is not a secret anymore.

Why does non-financial data pose such a great danger? Since they don’t need card numbers if they have the identity context. Something mentioning the customer’s airport, parking history, postcode or vehicle can masquerade as a legitimate refund, booking change, parking ticket or security notification. Those details can be weaponized and turned into customized phishing calls, emails and messages by artificial intelligence. Vehicle registration and travel patterns may reveal physical-world routines as well.

The UK GDPR requires organizations to minimize retained data, utilize risk-appropriate security and notify qualifying breaches. Compliance can hardly mean creating a bulky archive of surveillance you never had to do anything else with except document.

Advertisement

An independent investigation commission by MAG, a technical root-cause report and specific identification of the data categories here period processor and customers affected. It should pay for identity-monitoring and anti-fraud assistance, rather than just telling victims to “stay alert”.

All API keys should be categorized, rotated and eliminated from client-side code; privileges should be limited, unusual bulk exports should be blocked automatically and third-party marketing systems should be separated from operational infrastructure. Historic records of people logging into Wi-Fi and travel services, but for which a defensible purpose does not survive, must be deleted.

The ICO needs to look at data minimisation, retention, oversight and security controls of processing not simply what MAG did following discovery. Mandatory NCSC standards for the aviation sector on exposed secrets, access by vendors and bulk-data exfiltration.

Thirdly, the UK should ban ransom payment by private operators of critical transport infrastructure and establish a secret reporting channel and fund to compensate victims.

Refusing payment denies criminals profit. The goal is to strip them of their power that comes with the breach being effective. The first was accomplished by MAG; the second, however, has flummoxed regulators.

Advertisement

Fransiscus Nanga Roka

Faculty of Law University 17 August 1945 Surabaya and Managing Partner Law Firm Victorious Indonesia

Continue Reading
Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending Contents

Topical Issues

Cybercrime Cybercrime
Forgotten Dairies5 hours ago

DiaSorin’s Ransomware Claim Exposes a Dangerous Information Vacuum -By Fransiscus Nanga Roka

In Italy, national cybersecurity agency, a govet body coordinating between all other departments sec. privacy regulator; financial-market regulator; police and...

Christopher-Musa Christopher-Musa
Breaking News8 hours ago

2027 Elections: Gen Musa Predicts APC Victory in Kaduna, Tinubu Presidency

Gen Christopher Musa has expressed confidence that President Bola Tinubu will retain the Presidency and the APC will win Kaduna...

Forgotten Dairies9 hours ago

The Reacue Culture Under CAMA 2020: Has Nigeria Truly Moved Beyond Liquidation? -By Oluwaleye Adedoyin Grace

These developments weaken any suggestion that the rescue provisions are merely theoretical. At the same time, isolated successful cases cannot...

Blaise Udunze Blaise Udunze
Forgotten Dairies10 hours ago

Who exactly governs Nigeria: Abuja, Washington, or London? -By Blaise Udunze

The more important question is this: What will Nigeria do with the facts once they are known? Will Nigerian institutions...

PETER OBI PETER OBI
Breaking News10 hours ago

2027 Election: Obi Charges Rivers Residents to Defend Their Votes

NDC’s Peter Obi calls on Rivers voters to defend their mandate and demand credible, transparent elections in 2027.

Trump Trump
Breaking News13 hours ago

Trump Administration Turns Deportation Into Arcade Games, Draws Criticism From Rights Groups

Trump’s White House has launched arcade-style video games promoting deportation and border-wall policies, drawing criticism from migrant rights groups.

Media Chat - Wike Media Chat - Wike
Breaking News13 hours ago

2027 Presidency: Wike fears ‘payback’ from Atiku, Obi because he ‘injured’ them politically — Olayinka

Wike aide Lere Olayinka says the FCT minister is a realist and should expect political payback from Atiku or Peter...

Nigeria-Bandit-Fulani herdsmen-Crisis-Protest Nigeria-Bandit-Fulani herdsmen-Crisis-Protest
Forgotten Dairies14 hours ago

Our Roads, Their Hunting Ground: The Kidnapping Crisis In Kogi -By Idris Rufai

If the government fails to protect citizens from persistent insecurity, it risks losing the confidence of the very people it...

Livestock disease Livestock disease
Forgotten Dairies15 hours ago

Lumpy Skin Disease: A Growing Challenge for Cattle, Farmers, and Livestock Production -By Dr. Moris Umoru, DVM

The disease also reminds us that livestock health is closely connected to economic and social well-being. A healthy herd supports...

Forgotten Dairies15 hours ago

Dear Olumhense, I Am Not Stupid! -By Abdulkadir Salaudeen

Being asked by foreigners whether our president is a criminal is a question I do not want to answer. Besides,...