Tendvane

← All articles

SecuritySeptember 3, 2026

The Manchester Airports data is no longer just stolen. It has been published

A week ago the question for Manchester, Stansted and East Midlands passengers was whether their details had been taken. That's settled now. The group calling itself FulcrumSec has published the stolen data on its own site, and on 3 September it added a detail to the arithmetic: the 86 GB it first claimed was its compressed archive, and the exported files run to roughly 640 GB unpacked. We covered the original disclosure in last week's post.

Have I Been Pwned loaded the set on 2 September: 8.8 million accounts, with names, email addresses, phone numbers, IP addresses, browser details, locations, purchase records and vehicle registration plates. That last one comes from car-park bookings. The samples also hold booking references, prices paid, parking dates and times, and, according to the group, nearly 200,000 records about travel still to happen during the rest of 2026. No card or bank details were in the affected system, and nothing published so far contradicts that.

The company says it has contacted everyone affected, including people with upcoming bookings, and repeats the line worth remembering: it will "never contact customers unexpectedly to request payment-card details, banking information, or passwords." Read that as a forecast. Someone who knows you're flying from Stansted on the 19th and parked in Meet and Greet can write a very convincing "your parking booking has a problem" email, so treat anything airport-flavoured that arrives before a trip as suspect until you've checked it through the app or site you booked with. And search your address on haveibeenpwned.com; it takes ten seconds.

Nothing on your PC can pull an email address back once it's out. What Tendvane can do is keep the machine that reads those emails patched, which is what its check for updates is for.

Sources

Download Tendvane