CyberSecurity SEE

FulcrumSec Takes Responsibility for Manchester Airport Group Breach

FulcrumSec Takes Responsibility for Manchester Airport Group Breach

A cyber threat group has reportedly taken responsibility for a significant data breach affecting the UK’s largest airport group, Manchester Airports Group (MAG). This group, identified as FulcrumSec, has allegedly leaked nearly all of the 550GB of data it stole online, raising serious concerns about the implications for both privacy and security.

According to the information posted by FulcrumSec on its leak site, they have made available around 549GB of uncompressed customer data. The group claims that this data represents what they term as “pure Personally Identifiable Information” (PII). If these allegations are accurate, they shed new light on an incident that has so far been shrouded in limited information.

The breach appears to have been made possible through the discovery of administrative keys for the customer engagement platform Iterable, which were reportedly embedded in the frontend JavaScript code of the three airports’ websites managed by MAG. FulcrumSec pointed out that these keys were not hidden away on obscure subdomains but instead were clearly visible on the root domain of the websites. They noted that “any of the millions of visitors to the site could have right-clicked ‘inspect’ and seen the keys just sitting there, plain as day.” This ease of access calls into question the security protocols that were supposed to protect sensitive information.

MAG operates three major airports: Manchester Airport, Stansted Airport, and East Midlands Airport. The recent claims made by FulcrumSec indicate that the information obtained during the breach spans a much broader range than MAG initially disclosed. The group asserts that it has exfiltrated close to 8.7 million customer profiles, each containing vital information such as email addresses, names, mobile numbers, hometowns, postcodes, and residential IP addresses. This extensive collection of personal data could potentially enable extremely convincing phishing attacks aimed at the victims.

The breach encompassed a staggering array of additional data points, including:

– Approximately 1.2 billion marketing events, incorporating data on sends, opens, and clicks.
– Nearly 2.5 million transactions, which detail every booking made by customers for services like parking, Fast Track, and airport lounges.
– Over 461,000 SMS messages containing sensitive information such as booking dates, car park details, and vehicle registration numbers, all presented in plain text.
– A database of 108,000 unique vehicle registration plates.
– Critical platform configuration data.

Adding a more concerning dimension to this breach, FulcrumSec claims to possess sensitive information regarding nearly 191,000 future bookings, inclusive of travel schedules, PII, and vehicle information. Such details not only expose individuals to identity theft but could also be exploited by criminals to target the homes of travelers while they are away. The group suggested that some of the individuals whose data has been compromised are likely to be public figures, including politicians and military personnel, based on the email addresses linked to the exposed bookings.

In light of these alarming claims, FulcrumSec stated that MAG chose not to meet their demands for a fee designed to safeguard passenger data. Consequently, they reportedly left the more sensitive aspects of the data leak intact, turning the situation into a public disclosure. The group commented, “Sadly MAG declined to pay the necessary fee to protect their passengers’ data, leaving us to remove the most sensitive parts … from the leak prior to publication.”

As it stands, these claims about the breach have yet to be fully validated, and MAG has not released any updates since its initial communication regarding the incident on August 27. The silence from MAG raises suspicions and aids in perpetuating concerns about the organization’s data security protocols and crisis communication strategies in the face of such a severe threat.

The ramifications of this data breach extend well beyond MAG, affecting the millions of customers whose personal information has potentially been compromised. As they confront the fallout, it remains critical for organizations of this magnitude to prioritize data protection measures to secure the trust and safety of their clientele.

Source link

Exit mobile version