Cybersecurity

Manchester Airports: API Keys Sat in Web Code 4 Years, 8.8M Hit

Published 2 min readBy NewUJ Editorial Desk

Updated factual errors corrected

Manchester Airports: API Keys Sat in Web Code 4 Years, 8.8M Hit
Photo: Fatih Renkligil / Wikimedia Commons (CC BY-SA 4.0)
0 0
XWhatsAppTelegramLinkedIn

Three server-side API keys for the email-marketing platform Iterable sat in the public JavaScript of Manchester Airports Group's airport websites for more than four years without ever being rotated, according to a technical analysis published Sept. 7 by security researcher Scott Helme. The keys could reach Iterable endpoints capable of exporting customer databases and deleting accounts, Helme writes, even though MAG's own code used them for nothing more than logging marketing-campaign pageviews.

Helme says he set out to test a specific claim rather than to originate one. The extortion group FulcrumSec had said it did not hack anything and simply read an API key out of the website's JavaScript — "a very specific, very checkable claim," in his words. Using the Internet Archive's CDX API, he pulled historical JavaScript bundles and dated each key: East Midlands exposed from June 23, 2022 until MAG revoked it on Aug. 16, 2026; Stansted from June 28, 2022 to Aug. 25, 2026; Manchester from July 11, 2022 to Aug. 27, 2026. He reports the keys are now disabled. Iterable's own documentation tells developers never to embed a server-side API key in client-side code.

The timeline behind that analysis runs back three weeks. MAG disclosed unauthorised access to customer data on Aug. 27. FulcrumSec claimed responsibility on Aug. 30, telling BleepingComputer it had obtained 86 GB of compressed data — roughly 640 GB once extracted — and published the files on its leak site on Sept. 3. Breach-notification service Have I Been Pwned added the incident on Sept. 2 and lists 8.8 million affected accounts, with names, email addresses, phone numbers, IP addresses, browser user-agent details, geographic locations, purchases and vehicle registration plates among the exposed data classes.

The root cause changes what the breach means for the people caught in it. A credential visible in a page's source for four years is not an intrusion that firewalls, phishing training or endpoint software would have caught, and several of the exposed categories are durable: a vehicle registration plate tied to a parking booking, or a record of when someone flew and from which terminal, cannot be reset the way a password can. For any other company running client-side code, the same check costs an afternoon.

What is still unsettled is scope. MAG has not confirmed FulcrumSec's figures for dataset size or the extent of exposed future-travel records. A MAG spokesperson told BleepingComputer the group is "confident that we have taken effective measures to protect our customers" and has contacted all those affected, including people with upcoming bookings; MAG said payment-card and bank-account information was not seen in the samples of stolen data it reviewed, and warned that it "would never contact customers unexpectedly to request payment-card details, banking information, or passwords." BleepingComputer reported no disruption to airport operations. Individual customers can check their own exposure through Have I Been Pwned.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.