Hackers who broke into Manchester Airports Group's systems have dumped the stolen data of 8.7 million people online, for free.
FulcrumSec, the group behind the attack, exfiltrated a 500GB database after compromising one of MAG's internal systems and pivoting to a database hosted by a third-party provider, according to MAG. The gang then tried to extort MAG, offering to keep the database private in exchange for payment. MAG refused, following standard law-enforcement guidance not to pay ransoms. FulcrumSec responded by publishing the full database on the dark web instead of walking away empty-handed.
The leak matters less for its headline number than for what's actually in it. Security researchers say most of the 8.7 million records are just email addresses collected through airport WiFi sign-ups, with a smaller set including phone numbers, postcodes, and vehicle registrations tied to parking or lounge bookings. No passwords or payment data were exposed, but that smaller subset is exactly the kind of specific detail that makes phishing emails convincing.
Refusing to pay was the textbook-correct move - paying just funds the next attack. But it also means nearly nine million people are now dealing with fallout from a decision that wasn't theirs to make, and the unanswered question of how attackers pivoted from MAG's network into a third-party database deserves more scrutiny than the ransom drama does.