The key was in the page source, so nothing had to be broken into
Event dated 1 September 2026 · Published 2 September 2026 · 4 sources
The word breach implies a boundary that was crossed. Somebody found a flaw, defeated a control, or persuaded a person — there is a moment where access was obtained that was not intended.
A key sitting in the JavaScript a website sends to browsers has no such moment. Every visitor received it, along with the images and the stylesheet. Finding it required opening the developer tools that ship with every browser, which is a thing a curious teenager does for fun.
How a secret ends up in the shop window
Not through carelessness so much as through a pattern that looks reasonable at every step. A marketing or engagement platform offers an integration. The documentation shows a snippet with a key in it. The snippet works when pasted into the page, and the page is where the developer is working.
Many such platforms issue two kinds of key — a public one meant for the browser and a privileged one meant for the server — and the difference is a paragraph in the documentation rather than anything the code enforces. Both are strings. Both work. Only one is safe where it was put.
So the failure is not a person being foolish. It is a design in which the safe and unsafe options are indistinguishable at the moment of use, and the unsafe one is what the example code contains.
Why nobody noticed for as long as it took
Because nothing was wrong. The site worked, the integration worked, and no alert exists for a page serving a string it should not. Vulnerability scanners look for flawed software; this was correct software given a credential it should never have held.
It is the same shape as the credentials this site has described all year — the ones nobody claims and nobody rotates — with the distinguishing feature that this one was in the most public place an organisation owns. An access review would never have found it, because access reviews enumerate accounts and this was a line in a file served to the internet.
What a car park booking actually says about you
Reporting lists the affected material as car park, lounge and fast-track bookings plus Wi-Fi registrations, with fields including email address, telephone number, postcode and vehicle registration. That reads like an ordinary set until the combination is considered.
A number plate identifies a specific vehicle. A postcode narrows where it is kept. A parking booking states, precisely, the dates on which the owner was not at home. Assembled, that is not a marketing list — it is a schedule of absences tied to an address and a car, which is a useful document for purposes that have nothing to do with computers.
None of those fields is sensitive on its own, which is exactly why they were collected without much thought. Harm here comes from the join, and no data classification scheme in common use rates a booking system by what its fields become when placed side by side.
What the reassurance covers
Payment information was not compromised, and airport operations, passenger safety and aviation security were unaffected. All of that is important and all of it is true, and it answers the question a regulator and a traveller due to fly tomorrow are asking.
It does not answer the question the 8.7 million people in the file are asking, which is about a different kind of exposure entirely. This is the third case this year — after a standalone system and a generator with no risk to the national grid — where an accurate official statement addresses a narrower question than the one it appears to settle.
The check that would have caught it
Reading your own website the way a stranger does. What a browser receives is a small, finite set of files, and scanning them for anything resembling a credential is a task that takes minutes to automate and can run on every deployment.
That is unglamorous and it is the entire fix for this class. The credential was not hidden anywhere clever. It was in the one part of the estate that is, by design, available to everybody — and the only reason it lasted is that nobody on the inside had thought to look at the site from the outside.