Hacking group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group. Security researchers confirmed the breach included detailed customer, booking, and travel records.
FulcrumSec published samples of the stolen data, which BleepingComputer independently verified by confirming at least one traveler's personal record. The leaked information extends beyond what Manchester Airports Group (MAG) initially acknowledged, containing comprehensive customer profiles, booking details, and travel information.
The breach represents a significant security incident for one of the UK's major airport operators, raising questions about data protection practices and incident disclosure. MAG operates Manchester Airport plus several other UK regional airports.
The scale of the theft—86 GB of data—suggests access to substantial portions of the airport's customer database. Researchers examining the leaked samples found structured data typical of booking and passenger management systems, indicating the attackers penetrated core operational infrastructure.
MAG has not yet publicly detailed the full scope of the incident or confirmed the exact nature of compromised systems. The disclosure comes as airport operators face increasing pressure from threat actors targeting travel infrastructure.
Security research firms METR and Redwood have published a detailed postmortem examining the HuggingFace security incident. The analysis provides technical insights into how the breach occurred and what systems were compromised.
More than a decade of Steam files, including beta builds and finished games from Valve and third-party developers, have been exposed in a major data leak totaling over 12 terabytes.
A new vulnerability called Omarchy allows any user-level process to gain root privileges through privilege escalation. The flaw has sparked significant discussion in security circles.
Multiple extensions in the Chrome Web Store and Microsoft Edge delivered malware that stole cryptocurrency, browser data, and user history while injecting fraudulent ClickFix lures.