Airport hackers publish personal data of judge, politicians and celebrities on the dark web

← Back to the feed

Airport hackers publish personal data of judge, politicians and celebrities on the dark web

Daily Mail · 2 hours ago

Hackers behind a cyber attack on Manchester, Stansted and East Midlands airports last month have published the personal data of around 8.7 million customers on the dark web, after the airports' operator, Manchester Airports Group (MAG), refused to pay an undisclosed ransom. Analysis by The Mail on Sunday found the leaked files include sensitive details belonging to a circuit judge, parliamentary staff, Home Office and Bank of England employees, members of the Armed Forces, and email addresses purportedly linked to celebrities and Premier League footballers, raising concerns about targeted fraud and security risks for high-profile individuals.

The breach, carried out by extortion group FulcrumSec on 22 and 23 August and confirmed by MAG on 27 August, exploited access to car park, lounge and fast-track bookings, as well as airport wifi sign-ups; no banking or payment details were taken. FulcrumSec said it withheld the future travel plans of almost 200,000 passengers from the published data due to the security risks involved, and blamed MAG for the leak, accusing it of negligence and downplaying the breach's scale. MAG has urged customers to be alert to scam calls, texts and emails, insisted passenger safety and airport operations remain unaffected, and said it is working with authorities and specialist advisers.

  • Hackers leaked data of 8.7m airport customers after MAG refused ransom
  • Judge, MPs' staff, Home Office and Bank of England staff exposed
  • No banking details stolen; MAG warns customers of possible scam attempts

New here? Start with this

Manchester Airports Group (MAG) runs three UK airports: Manchester, Stansted and East Midlands. Last month these airports were hit by a cyber attack, and the group has now confirmed that hackers have published personal data belonging to around 8.7 million customers on the dark web, a part of the internet not indexed by normal search engines and often used for illegal trading of stolen information.

The attack was carried out by a group calling itself FulcrumSec, which is reported to have demanded a ransom from MAG in exchange for not releasing the data. MAG says it refused to pay, after which the hackers went ahead and published the files. The stolen information came from systems handling car park bookings, airport lounges, fast-track security passes and wifi sign-ups, rather than from ticketing or payment systems, so no banking details are involved.

This matters because the leaked data reportedly includes personal details of a wide range of people, from ordinary travellers to a judge, government and Bank of England staff, military personnel and some well-known public figures. Incidents like this raise concerns about identity theft and scam attempts, since criminals can use leaked personal details to impersonate organisations or individuals in fraudulent calls, texts and emails.

Cybersecurity Technology World

Read the full article at the source →