Manchester Airports Group Data Breach

Alleged

Ransomware claim involving Manchester Airports Group

Published: Sep 1, 2026 FulcrumSec
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Manchester Airports Group
Industry
Transportation
Threat Actor
FulcrumSec
Date of Incident
Sep 1, 2026

Executive Summary

FulcrumSec posted Manchester Airports Group (MAG) to its dark web portal on September 1, 2026, an event flagged by SOCRadar Dark Web Monitoring. MAG is the United Kingdom’s largest airport operator outside Heathrow, managing Manchester Airport, East Midlands Airport, and London Stansted Airport. These airports collectively serve tens of millions of passengers annually, making MAG a critical piece of national transport infrastructure and a potentially attractive target for cybercriminals. The nature of its operations and the significant passenger volume it handles underscore the potential impact of a successful cyberattack. FulcrumSec has a limited observed history in SOCRadar’s dataset, with the listing of MAG being its only known claim within the last 60 days. The group’s specific targeting patterns are not yet firmly established. It remains unclear whether this incident represents a deliberate targeting of a high-profile entity or is the result of opportunistic credential access. However, the escalation in ambition, targeting critical infrastructure like MAG, is a notable development in their observed activity.

Technical Analysis

A stealer-log query for magairports[.]com revealed 25 records spanning July 13 through August 27, 2026. Of these, 11 records were classified as employee credentials, with a particular concentration on adfs.magairports[.]com, which serves as the primary Single Sign-On (SSO) gateway. The timeframe of these records, with the latest dating to August 27, 2026 – just five days before the listing – indicates that these credentials were likely active and potentially compromised at the time of publication. A critical detail emerging from the analysis is the presence of a single masked username appearing across seven records related to the ADFS main endpoint and a password-reset endpoint within the 45-day window. Furthermore, one record specifically targeted the ADFS password-reset flow. Three additional records were found to hit myroster.magairports[.]com, identified as the employee roster portal. This pattern of activity suggests a significant corporate intrusion risk. The concentration of activity on the ADFS gateway is a key indicator of potential risk. ADFS provides single sign-on capabilities across the entire organizational estate. Compromised credentials or tokens at this layer could enable threat actors to achieve lateral movement into crucial airport operational systems without encountering per-application authentication controls. The existence of seven records on a single identity at the ADFS gateway, coupled with a password-reset attempt, strongly resembles a typical pre-ransomware persistence fingerprint. Rotate ADFS credentials and audit identity provider logs from July 13 onward. Priority should be given to reviewing all federated access events and token issuance logs for the specified 45-day window.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.