Hackers linked to the cyber-extortion group FulcrumSec have published personal data of a judge, politicians, celebrities, and defence personnel on the dark web following a recent cyberattack on three major UK airports. The incident involved the theft of information belonging to an estimated 8.7 million customers who used Manchester, Stansted, and East Midlands airports.

The cyber breach occurred over two days, on August 22 and 23, targeting Manchester Airports Group’s (MAG) IT systems. MAG publicly confirmed the attack on August 27. According to the hackers, the stolen data includes records obtained through access to car park, lounge, and fast-track bookings, as well as users signing up for Wi-Fi services within the airports. MAG has stated that no banking or payment information was compromised.

Analysis of the leaked files reveals that the breach affected not only ordinary passengers but also individuals in sensitive positions. Among the records disclosed were travel details linked to a circuit judge using an official judicial email to book flights, employees from the Home Office and Bank of England, parliamentary workers, and members of the Armed Forces. Vehicle registration numbers, future travel itineraries, and email addresses allegedly belonging to celebrities and Premier League footballers were also exposed.

While FulcrumSec claimed to have acquired data revealing the future travel plans of nearly 200,000 passengers—which could potentially expose when individuals would be away from home—the group chose to withhold this portion from the public leak, citing security concerns. The hackers attributed the release of the other stolen information to MAG’s decision not to pay an undisclosed ransom demand. “MAG declined to pay the necessary fee to protect their passengers’ data, leaving us to remove the most sensitive parts… from the leak prior to publication,” a statement from the group said. FulcrumSec further accused the airport operator of minimizing the breach’s severity and being negligent in protecting customer information.

In response, MAG advised customers to be vigilant against potential scams after the hack, emphasizing that it would never initiate unexpected requests for payment or banking details. The company asserted that it had swiftly contained the risk, engaged specialist advisers, and taken appropriate measures to safeguard customer data and its systems. MAG also confirmed that it is cooperating with relevant authorities and stated that airport operations, including customer parking services, continue to function normally. The operator assured the public that passenger safety and aviation security have not been compromised and expressed regret for any inconvenience caused.

The ongoing investigation underscores the challenges airports and critical infrastructure face from increasingly sophisticated cyber threats, highlighting the importance of robust cybersecurity measures in protecting personal data.