Security boffin claims airport group left API keys in client-side JavaScript for four years
Security researcher Scott Helme says his own investigation corroborates claims by extortion group FulcrumSec that Manchester Airports Group (MAG) exposed privileged API keys for the Iterable marketing platform in publicly accessible JavaScript on the websites of Manchester, Stansted and East Midlands airports. Helme used the Wayback Machine to show the keys had been embedded in front-end code since 2022 and remained there until August 2026, meaning anyone inspecting the page source over four years could have harvested them — a serious lapse given the data allegedly belonging to 8.8 million customers was stolen last month.
Helme found the keys were far more privileged than needed for their stated purpose of tracking marketing email clicks, granting read/write access to customer profiles, parking and lounge bookings, and Fast Track purchases, as well as the ability to delete records entirely — meaning the attackers could potentially have wiped MAG's database rather than merely copying it. MAG has called the breach "sophisticated" and "a hack, not a lapse," declined to comment on Helme's findings, and disputes his characterisation, while continuing to work with the ICO and National Crime Agency. FulcrumSec published the stolen data on 2 September after MAG refused to pay a ransom the ICO said was lower than typical extortion demands.
- Researcher says MAG exposed Iterable API keys in public JavaScript since 2022
- Overprivileged keys reportedly let attackers read and could delete 8.8m records
- MAG disputes claims, calls it a hack; ICO and NCA now involved