GCS Threat Briefing
Data Governance

The Key Was In The Page Source

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
September 2026 · 7 min read
GCS Threat Briefing cover: The Key Was In The Page Source. A dark brand panel showing an API credential inside a website script tag connecting to a marketing platform and out to a customer database, in Garzon Cyber Solutions red and white.

Manchester Airports Group has confirmed a breach affecting around 8.7 million people across Manchester, London Stansted and East Midlands. BleepingComputer describes it as the largest known customer data breach at a British airport operator. The extortion group that claimed it says it used an API credential MAG had published in the front-end code of its own website. On that account, the access needed no exploit, no malware and no phishing.

That claim is unverified. It is also completely unremarkable, which is the reason to write about it. Secrets left in client-side code is one of the oldest findings in application security. It survives because the code in question is usually deployed by marketing, and the platform it unlocks was usually bought by marketing too.

8.7mCustomers affected, per MAG
86 GBVolume claimed by the attacker
200,000Claimed records on travel still to come in 2026
ZeroVulnerabilities exploited, on the account given

What happened

  • 27 August 2026MAG discloses that an unauthorised third party stole customer data tied to car park, lounge and Fast Track bookings and in-airport Wi-Fi registrations. It names email addresses, phone numbers, vehicle registration numbers and postcodes. No payment details were accessed. No operational disruption. The online Manage My Booking service is suspended as a precaution, access to affected systems restricted, external experts engaged, law enforcement notified.
  • 27 August 2026The Manchester Evening News reports the figure, citing private MAG statements, initially at up to 8.9 million travellers and subsequently at around 8.7 million with email addresses only for the vast majority. BleepingComputer says it cannot confirm the number. No group has claimed the attack.
  • 30 August 2026The extortion group FulcrumSec claims responsibility, supplies samples, and says it took roughly 86 GB. BleepingComputer validates one traveller's record against that person's known Manchester Airport purchase history: previous Fast Track purchases, booking and arrival times, terminal used, amounts paid, purchase references and total spending. The samples supplied are said to include a roughly 21.5 GB Manchester customer export of consolidated profiles, a figure BleepingComputer reports rather than confirms.
  • 30 August 2026Asked directly about the 86 GB claim, the exposed credentials and the future-travel data, a MAG spokesperson declines to address the specific claims and points to a statement that affected customers have been contacted, including everyone with an upcoming booking.
  • 1 September 2026The Cyber Security and Resilience Bill enters Committee stage in the House of Lords, carrying a 24-hour reporting clock and penalties of up to £17 million or 4% of global turnover.

Why this one is different

FulcrumSec says it obtained airport-specific Iterable API credentials exposed in client-side JavaScript. Iterable is a marketing automation platform. Read carefully, the claim does not allege that Iterable was breached. It places the credential in MAG's own public web code, where any visitor with a browser could read it.

If that is what happened, three separate controls were never in the path.

Patch management did not apply. There is no CVE, no advisory, no vendor fix and nothing to schedule. The vulnerability management programme that consumes the largest share of most UK security budgets had no role to play.

Detection had nothing to find. An API call to a marketing platform, carrying a valid credential, is indistinguishable from that platform working as designed. There is no anomaly, because the behaviour is normal.

The sector regulator was looking elsewhere. Under the Network and Information Systems Regulations 2018, the owner or manager of an aerodrome handling more than 10 million terminal passengers a year is an operator of essential services, with the Civil Aviation Authority and the Department for Transport acting as joint competent authority. Manchester and London Stansted clear that threshold; East Midlands does not. Either way the regime is built around continuity of the essential service. Operations were unaffected and aviation security was not compromised. The regulator that oversees the airport is not the regulator interested in the data.

GCS infographic titled Three Controls, None In The Path. Three dark brand panels explain that patch management had no CVE to act on, detection saw a valid credential calling a marketing API, and the aviation regulator oversees service continuity rather than customer data.
On the account given, the access route sat outside every control a UK board is used to funding. Source: MAG statement, 27 August 2026; FulcrumSec claims via BleepingComputer, 30 August 2026; NIS Regulations 2018.

There is a second point, and it changes the harm class. FulcrumSec claims that nearly 200,000 of the records relate to travel still to come during the remainder of 2026, with dates, times and booking information tied to identifiable individuals. If accurate, that is not a privacy exposure. It is a physical one: who is away from home, when, and from which terminal. FulcrumSec has said it is weighing whether to withhold or redact those specific records because of the potential for real-world harm. An extortion group is applying a harm test that the victim's own disclosure did not.

Then there is the scope gap. MAG named four categories of data. The samples reviewed by BleepingComputer held considerably more: purchase and booking references, airport and product selections, prices, discounts, booking status, parking dates and times, historical spending, IP addresses, approximate locations, device information and customer-engagement data. UK postcodes carry weight here that US postal codes do not. The Office for National Statistics puts a typical small-user postcode at around 15 addresses, while some postcodes are assigned to a single address. Postcode plus vehicle registration plus parking dates is close to an address and a movement pattern.

Not an isolated case

Look at the other large data loss of the same fortnight. ShinyHunters told BleepingComputer it reached McKesson through voice phishing calls to employees, used the credentials to take over Okta single sign-on accounts, and moved from there into Salesforce and Snowflake. McKesson confirmed on 28 August that it was investigating an incident involving third-party applications and unauthorised access and exfiltration of data. The group's figure of 284 million records is its own claim and reflects database rows rather than individuals.

Two of the largest data extortion events of the past fortnight. Between them, on the accounts given, not one exploited vulnerability. One used a credential the victim published. The other used a phone call.

Most enterprise security spending still assumes attackers break in. Increasingly they log in, using credentials that are valid, into platforms the security function did not procure.

The commercial exposure for UK organisations

Regulatory. Capita is the precedent every UK board should have in front of it. In October 2025 the Information Commissioner's Office settled at £14 million, reduced from a proposed £45 million, over a 2023 breach affecting 6.6 million people. Three failings were cited, one of which was a 58-hour delay in quarantining a device against a one-hour internal target. Where the ICO finds a breach of the security principle, UK GDPR caps penalties at £17.5 million or 4% of annual global turnover, whichever is higher. MAG reported group revenue of £1.5 billion, which would put the theoretical higher-tier ceiling near £60 million. Read that as a ceiling and not a forecast. Capita's dataset included criminal records and special category data, where MAG's is email addresses only for the vast majority of the 8.7 million, and the outcome there was £14 million. Separately, since 5 February 2026 the Data (Use and Access) Act 2025 has raised maximum penalties for serious breaches of the Privacy and Electronic Communications Regulations to UK GDPR levels, which is directly relevant when the dataset in question was assembled for marketing.

Financial. Notification at this volume is not a line item. It is 8.7 million contact records, a suspended booking channel, external incident response, and a customer base now primed for exactly the impersonation that the stolen fields enable.

Contractual. Corporate parking, lounge and travel agreements carry data protection terms, as does every processor arrangement covering a marketing platform. Where the access route is a credential the controller exposed, the processor's liability position is strong and the controller's is not.

Governance. This is the one that matters, and it generalises well beyond MAG. If the claimed route is accurate, the pattern is a familiar one in almost every large organisation: the dataset is a marketing asset, the platform was bought by marketing, the credential sits in code deployed by a web team, and the consequence lands with the board. Between the decision and the consequence there is no security owner. None of the reporting establishes who procured or deployed what at MAG, and the point does not depend on it.

GCS infographic titled The Numbers That Matter. A dark brand panel setting 8.7 million affected customers and MAG group revenue of one and a half billion pounds against the Capita precedent of a fourteen million pound ICO settlement for a breach affecting 6.6 million people.
The regulatory ceiling is set by turnover, and the precedent is set by Capita. Sources: ICO, October 2025; MAG Annual Report 2026; BleepingComputer, 30 August 2026.

What leaders should do this week

  1. Commission a client-side secrets audit across every public web property, including tag manager containers and third-party scripts nobody in your organisation wrote. Ask for the result in writing. A verbal assurance from the team that deployed the code is not a control.
  2. Name one accountable owner for every SaaS platform holding customer data, including the platforms security did not buy. One human name each. A platform with no name against it is itself the finding.
  3. Put the marketing and analytics estate into assessment scope. Most penetration testing scopes stop at the applications IT owns. The dataset that actually leaves is rarely in one of them.
  4. Reconcile your disclosure with what an attacker could plausibly hold. Announcing four categories of data and having eleven surface later is a second incident, and it is a governance one.
  5. Rehearse an incident with no malware in it. If your playbook opens with endpoint containment and forensic imaging, it does not fit this case, and this case is becoming the common one.
GCS infographic titled Five Decisions For This Week. A numbered dark brand checklist covering a client-side secrets audit, naming an owner for every customer-data platform, widening assessment scope to marketing and analytics, reconciling disclosure with attacker-held data, and rehearsing an incident with no malware in it.
Five decisions an executive can take without a technical briefing. Garzon Cyber Solutions, September 2026.

Three questions for the board

  1. Who is accountable for the customer data held in platforms that our security function did not buy?
  2. If a credential to one of those platforms were published in our website code today, which control would find it, and how long would that take?
  3. Does our breach notification describe the fields we have confirmed, or the fields an attacker plausibly holds?

The strategic takeaway

The security programme most UK boards have funded is built to stop intrusion. Two of the past fortnight's largest data losses did not involve one. Exposure has moved to the platforms that hold customer data outside the security perimeter, bought by functions with no security reporting line, reached with credentials that are entirely valid. That is an ownership problem before it is a technical one, and ownership is decided at board level, not in the SOC.

Confidence note

Confirmed. MAG's disclosure of 27 August and its contents, the affected airports and booking channels, the four data categories MAG named, that operations were unaffected and payment data was not accessed, the suspension of Manage My Booking, and the figure of around 8.7 million as given by a MAG spokesperson to the Manchester Evening News. McKesson's statement of 28 August. The ICO's £14 million Capita settlement of October 2025. The Cyber Security and Resilience Bill entering Lords Committee stage on 1 September 2026.

Claimed by the attacker and not independently verified. The 86 GB volume, the Iterable API credential route, the roughly 200,000 upcoming-travel records and the 21.5 GB Manchester export. ShinyHunters' figure of 284 million records at McKesson is likewise the group's own claim. BleepingComputer validated one MAG record against a traveller's known purchase history and reviewed samples containing categories beyond MAG's disclosure, while stating explicitly that it could not verify the alleged source or extent of access, the overall dataset size, or the upcoming-travel claim.

Assessed rather than established. That the exposure route was a credential on the controller's side rather than a compromise of the platform itself. Nothing in the reporting alleges that Iterable was breached, and the claim as stated places the credential in MAG's own client-side code.

One discrepancy on the record. The Manchester Evening News first reported up to 8.9 million, citing private MAG statements, and subsequently around 8.7 million. Both figures come from the same reporting thread rather than from two independent sources, and MAG has not published a number itself. The 21.5 GB export figure is likewise reported rather than confirmed.

Who owns the platforms your security team did not buy?

Garzon Cyber Solutions is built to map customer data to accountable owners, bring the platforms outside the security perimeter into assessment scope, and put the people in place to keep it that way. Cybersecurity, compliance and specialist recruitment, offered as one capability.

Start the Conversation →
Subscribe to GCS Insights
Sources
Manchester Airports Group, Data Security Incident statement, 27 August 2026 · BleepingComputer, "Manchester Airports Group says hackers stole travelers' data", Bill Toulas, 27 August 2026 · BleepingComputer, "FulcrumSec claims Manchester Airports hack, theft of 86 GB of data", Ax Sharma with Bill Toulas, 30 August 2026 · Manchester Evening News, 27 August 2026 · Information Commissioner's Office, "Capita fined £14m for data breach affecting over 6m people", 15 October 2025, and the accompanying monetary penalty notice · The Network and Information Systems Regulations 2018, SI 2018/506 · UK Civil Aviation Authority, Cyber Security Regulation · Office for National Statistics, UK postal geography · BleepingComputer, Help Net Security and HIPAA Journal on the McKesson disclosure and the ShinyHunters claims, 28 to 31 August 2026 · UK Parliament, Cyber Security and Resilience (Network and Information Systems) Bill, Lords Committee stage, 1 September 2026.
Data Breach Third Party Risk UK GDPR Governance Critical National Infrastructure

Garzon Cyber Solutions delivers cybersecurity advisory, compliance certification and specialist technology recruitment as one integrated capability. We are a young firm, the founder personally runs the work, and our perspective comes from a career spent selling cybersecurity, compliance and technology to security and technology buyers across the UK, EU and Americas.