Manchester Airports: API Keys Sat in Web Code 4 Years, 8.8M Hit

Three server-side API keys for the email-marketing platform Iterable sat in the public JavaScript of Manchester Airports Group's airport websites for more than four years without ever being rotated, according to a technical analysis published Sept. 7 by security researcher Scott Helme. The keys could reach Iterable endpoints capable of exporting customer databases and deleting accounts, Helme writes, even though MAG's own code used them for nothing more than logging marketing-campaign pageviews.
Helme says he set out to test a specific claim rather than to originate one. The extortion group FulcrumSec had said it did not hack anything and simply read an API key out of the website's JavaScript — "a very specific, very checkable claim," in his words. Using the Internet Archive's CDX API, he pulled historical JavaScript bundles and dated each key: East Midlands exposed from June 23, 2022 until MAG revoked it on Aug. 16, 2026; Stansted from June 28, 2022 to Aug. 25, 2026; Manchester from July 11, 2022 to Aug. 27, 2026. He reports the keys are now disabled. Iterable's own documentation tells developers never to embed a server-side API key in client-side code.
The timeline behind that analysis runs back three weeks. MAG disclosed unauthorised access to customer data on Aug. 27. FulcrumSec claimed responsibility on Aug. 30, telling BleepingComputer it had obtained 86 GB of compressed data — roughly 640 GB once extracted — and published the files on its leak site on Sept. 3. Breach-notification service Have I Been Pwned added the incident on Sept. 2 and lists 8.8 million affected accounts, with names, email addresses, phone numbers, IP addresses, browser user-agent details, geographic locations, purchases and vehicle registration plates among the exposed data classes.
The root cause changes what the breach means for the people caught in it. A credential visible in a page's source for four years is not an intrusion that firewalls, phishing training or endpoint software would have caught, and several of the exposed categories are durable: a vehicle registration plate tied to a parking booking, or a record of when someone flew and from which terminal, cannot be reset the way a password can. For any other company running client-side code, the same check costs an afternoon.
What is still unsettled is scope. MAG has not confirmed FulcrumSec's figures for dataset size or the extent of exposed future-travel records. A MAG spokesperson told BleepingComputer the group is "confident that we have taken effective measures to protect our customers" and has contacted all those affected, including people with upcoming bookings; MAG said payment-card and bank-account information was not seen in the samples of stolen data it reviewed, and warned that it "would never contact customers unexpectedly to request payment-card details, banking information, or passwords." BleepingComputer reported no disruption to airport operations. Individual customers can check their own exposure through Have I Been Pwned.
Sources
- Scott Helme — No Hacking Required: The Manchester Airports Group Data BreachSecondary
- BleepingComputer — FulcrumSec claims Manchester Airports hack, theft of 86 GB of dataSecondary
- Have I Been Pwned — Manchester Airports Group breach recordSecondary
- The Register — Security boffin claims airport group left API keys in client-side JavaScript for four yearsSecondary
Related
Revolut Breach: Attackers Demanded 10,000 Bitcoin Ransom
Sogou Flaw Let One Click Backdoor an App Used by 455M a Month
CISA Adds 5 Exploited Flaws; ScreenConnect Rated CVSS 9.9
GitLab CVSS 10.0 Flaw Exploited; CISA Deadline Is September 14
Chrome 153 Fixes 7th Exploited Zero-Day of 2026: CVE-2026-87491
Sandworm, Qilin Exploit Cisco Firewall Flaw Rated CVSS 10.0
IDScan.net Confirms Breach After 153M ID Scans Offered on Dark Web
Microsoft Fixes 2 Exploited Windows Zero-Days; CISA Sets Sept. 22
Trending now
- VW Mission Efficiency Sets 0.158 Cd World Record
- Marvel's Wolverine Lands on PS5 With a 77 Metascore
- Revolut Breach: Attackers Demanded 10,000 Bitcoin Ransom
- Saudi Pipeline Repairs to Take Weeks as Brent Tops $107
- US Diesel Sets Record $6.23 a Gallon, AAA Figures Show
- Sogou Flaw Let One Click Backdoor an App Used by 455M a Month
- DeepMind AGI Safety Researcher Quits, Turns Down Anthropic, OpenAI
- Apple Ships iOS 27 With Siri AI, but Not for EU iPhones
Comments
No comments yet. Be the first.