Forgotten Dairies

No Ransom Paid, But Millions Still Pay -By Fransiscus Nanga Roka

Refusing payment denies criminals profit. The goal is to strip them of their power that comes with the breach being effective. The first was accomplished by MAG; the second, however, has flummoxed regulators.

Published

on

Manchester Airports Group does not pay cyber extortion. That was the correct decision. It does not turn MAG into a protagonist in a narrative where roughly 8.7 million customers also lost track of their data.

Discovered in late August 2026, the breach hit databases underpinning Manchester, London Stansted and East Midlands airports. This was linked to registrations and bookings at airports done via Wi Fi — and for parking, lounges and Fast Track services. MAG said that the email addresses, telephone numbers, postcodes and vehicle registrations were accessed. The bank and payment information was not stored on the purchased system, it said, as were aviation security operations, such as passenger safety and airport operation.

Those assurances cover what didn’t happen. They do not function as a counterbalance to what did.

After MAG refused the ransom demand, the extortion group FulcrumSec emerged and allegedly released data on 8.7 million individuals. That leak has also now been added to the Have I Been Pwned catalog of breaches, which lists names, contacts, IP addresses geolocation data, browser fingerprints and purchase and vehicle-registration numbers among the affected hit-by-breach categories.

How did the attackers enter? FulcrumSec said it discovered airport-specific credentials for the Iterable marketing platform which had been exposed in client-side JavaScript. It is also said to have retrieved around 86GB of compressed data and around 200,000 records relating to travel into the future.

Advertisement

These allegations are serious, but remain attacker claims rather than regulatory conclusions. Their public announcement does not state if the theory around the API-key is accurate, or if 86GB figure, and a 550GB extracted archive of an FSYX future-itinerary dataset. It has not yet been established what the technical cause was that led to the hours-long outage on December 13, or who would be legally responsible for it, with no public finding from Information Commissioner’s Office (ICO) yet made.

That matters because extortionists weaponize publicity as strategically as they weaponize the stolen data. Spread their marketing copy as forensic fact, not journalism scrutinising their evidence.

Even so MAG cannot hide behind uncertainty. Embedding a privileged API credential in publicly accessible code is not sophisticated intrusion, it is institutional negligence automated at scale. A secret stored in a browser is not a secret anymore.

Why does non-financial data pose such a great danger? Since they don’t need card numbers if they have the identity context. Something mentioning the customer’s airport, parking history, postcode or vehicle can masquerade as a legitimate refund, booking change, parking ticket or security notification. Those details can be weaponized and turned into customized phishing calls, emails and messages by artificial intelligence. Vehicle registration and travel patterns may reveal physical-world routines as well.

The UK GDPR requires organizations to minimize retained data, utilize risk-appropriate security and notify qualifying breaches. Compliance can hardly mean creating a bulky archive of surveillance you never had to do anything else with except document.

Advertisement

An independent investigation commission by MAG, a technical root-cause report and specific identification of the data categories here period processor and customers affected. It should pay for identity-monitoring and anti-fraud assistance, rather than just telling victims to “stay alert”.

All API keys should be categorized, rotated and eliminated from client-side code; privileges should be limited, unusual bulk exports should be blocked automatically and third-party marketing systems should be separated from operational infrastructure. Historic records of people logging into Wi-Fi and travel services, but for which a defensible purpose does not survive, must be deleted.

The ICO needs to look at data minimisation, retention, oversight and security controls of processing not simply what MAG did following discovery. Mandatory NCSC standards for the aviation sector on exposed secrets, access by vendors and bulk-data exfiltration.

Thirdly, the UK should ban ransom payment by private operators of critical transport infrastructure and establish a secret reporting channel and fund to compensate victims.

Refusing payment denies criminals profit. The goal is to strip them of their power that comes with the breach being effective. The first was accomplished by MAG; the second, however, has flummoxed regulators.

Advertisement

Fransiscus Nanga Roka

Faculty of Law University 17 August 1945 Surabaya and Managing Partner Law Firm Victorious Indonesia

Leave a Reply

Your email address will not be published. Required fields are marked *

Exit mobile version