Skip to content
The Cyber Security Place

The key was in the page source, so nothing had to be broken into

Event dated 1 September 2026 · Published 2 September 2026 · 4 sources

Data belonging to around 8.7 million customers of Manchester Airports Group — covering Manchester, London Stansted and East Midlands — was taken and posted for download by a group calling itself FulcrumSec, which claimed responsibility on 1 September 2026 and put the volume at roughly 549GB. According to reporting, initial access came from administration keys for a customer engagement platform found in the frontend JavaScript of all three airport websites. If that account holds, the credential was not stolen. It was published, to every visitor who loaded a page, for as long as it was there.

The word breach implies a boundary that was crossed. Somebody found a flaw, defeated a control, or persuaded a person — there is a moment where access was obtained that was not intended.

A key sitting in the JavaScript a website sends to browsers has no such moment. Every visitor received it, along with the images and the stylesheet. Finding it required opening the developer tools that ship with every browser, which is a thing a curious teenager does for fun.

How a secret ends up in the shop window

Not through carelessness so much as through a pattern that looks reasonable at every step. A marketing or engagement platform offers an integration. The documentation shows a snippet with a key in it. The snippet works when pasted into the page, and the page is where the developer is working.

Many such platforms issue two kinds of key — a public one meant for the browser and a privileged one meant for the server — and the difference is a paragraph in the documentation rather than anything the code enforces. Both are strings. Both work. Only one is safe where it was put.

So the failure is not a person being foolish. It is a design in which the safe and unsafe options are indistinguishable at the moment of use, and the unsafe one is what the example code contains.

Why nobody noticed for as long as it took

Because nothing was wrong. The site worked, the integration worked, and no alert exists for a page serving a string it should not. Vulnerability scanners look for flawed software; this was correct software given a credential it should never have held.

It is the same shape as the credentials this site has described all year — the ones nobody claims and nobody rotates — with the distinguishing feature that this one was in the most public place an organisation owns. An access review would never have found it, because access reviews enumerate accounts and this was a line in a file served to the internet.

What a car park booking actually says about you

Reporting lists the affected material as car park, lounge and fast-track bookings plus Wi-Fi registrations, with fields including email address, telephone number, postcode and vehicle registration. That reads like an ordinary set until the combination is considered.

A number plate identifies a specific vehicle. A postcode narrows where it is kept. A parking booking states, precisely, the dates on which the owner was not at home. Assembled, that is not a marketing list — it is a schedule of absences tied to an address and a car, which is a useful document for purposes that have nothing to do with computers.

None of those fields is sensitive on its own, which is exactly why they were collected without much thought. Harm here comes from the join, and no data classification scheme in common use rates a booking system by what its fields become when placed side by side.

What the reassurance covers

Payment information was not compromised, and airport operations, passenger safety and aviation security were unaffected. All of that is important and all of it is true, and it answers the question a regulator and a traveller due to fly tomorrow are asking.

It does not answer the question the 8.7 million people in the file are asking, which is about a different kind of exposure entirely. This is the third case this year — after a standalone system and a generator with no risk to the national grid — where an accurate official statement addresses a narrower question than the one it appears to settle.

The check that would have caught it

Reading your own website the way a stranger does. What a browser receives is a small, finite set of files, and scanning them for anything resembling a credential is a task that takes minutes to automate and can run on every deployment.

That is unglamorous and it is the entire fix for this class. The credential was not hidden anywhere clever. It was in the one part of the estate that is, by design, available to everybody — and the only reason it lasted is that nobody on the inside had thought to look at the site from the outside.