8.7 Million People, One Cracked Foundation
UPDATE
Since this piece went live, the likely way in has surfaced, and it sharpens every point mentioned in the original post.
The group claiming the breach, FulcrumSec, told BleepingComputer it didn't need to hack anything. It read an Iterable API key straight out of the airports' website code. Security researcher Scott Helme checked the claim himself and found 3 keys, one per airport, sitting in the page source, unrotated for more than FOUR YEARS. MAG has not officially confirmed the vector, so adding allegedly all over this.
But, if it holds, the fundamentals argument has absolutely nowhere left to hide. A credential is a door and this one sat propped open in public since 2022 (allegedly). Machine identity governance is the exact check that rotates that key and closes that door, and it costs a fraction of what a breach of 8.7 million people costs.
The floor question comes down to one thing here: a key nobody rotated for 4 years.
Fix the floor. Then bring the robots.
The Manchester Airports breach is a fundamentals story. The way the internet treats people who protect themselves makes it worse.
Manchester Airports Group lost data belonging to almost 8.7 million customers.
Email addresses.
Phone numbers.
Vehicle registrations.
Postcodes.
The most disturbing is this: the vast majority of it came from what most everyone wants when they in sequestered in an airport waiting for a flight. Free airport WiFi.
The attackers stole the data and true to form demanded a ransom. MAG refused to pay. While the ransom standoff raged on, flights kept running, payment cards stayed out of reach, and the company reported the incident to the Information Commissioner's Office and theNational Cyber Security Centre. And impacted customers got an email telling them there was nothing they needed to do.
While the communication is nothing to really see, nothing for one to do here, there’s so much here that should bother you, so let me tell you which part.
Nobody needs the vector to see the problem
MAG hasn’t said how the attackers got in. So, I’m not going to spend cycles and delve into conspiracy theories to guess, and you should give anyone the side eye who tries names a cause this early. No need to go down that rabbit hole because one can read the tea leaves without the naming the exact vector.
How? Well, there are two confirmed facts that carry the entire story.
- The intrusion ran across a weekend and got caught on a Tuesday. We all love our weekends but someone who shouldn’t been there was livin’ la vida loca inside those systems for days before a single alarm went off. Detection was abysmally slow, which tells you the monitoring was quiet where it needed to be loud.
- The stolen data sat in the systems that run parking, lounges, Fast Track, and WiFi signups. The “convenience” layer. The stuff bolted onto the edge of airport operations to smooth, reduce friction and annoyance of a passenger’s journey and, of course, sell you the convenience, skip the line and reduced annoyance as an upgrade.
And both facts point at, you guessed it, the fundamentals.
Now, let’s ask the questions that decide the size of a breach.
Why did a WiFi signup capture a phone number at all?
Who and what could reach that data once it was collected?
Was the convenience layer walled off from anything of real value, or did it share a floor with it?
How long could an intruder wander before the building noticed?
Straight up answer those and you’ve described the difference between an incident and a catastrophe. And none of them require knowing which door the attacker used to get in.
Airports keep getting hit the same way.
So, this is a pattern, not a one-off.
In September 2025, a ransomware attack on Collins Aerospace check-in software knocked out systems at Heathrow, Brussels, and Berlin. Attackers walked right past the flight-critical fortress and went through the side entrance: the 3rd party software that checks you in, parks your car, and waves you into the lounge. And here’s the lesson for everyone who has a supply chain – you are only as strong as your weakest link. Doesn’t matter that you’ve done all the right things, if there is anyone in your supply chain or your supplier’s supply chain that is vulnerable, so are you.
So, the lesson repeats.
The most vulnerable underbelly of aviation is the ancillary (i.e., the convenience) tech that touches customers. Operators pour their hardening resources into the systems that keep planes in the air (which is critical, of course), and they treat the parking database at worse like the red-headed stepchild or at best a rounding error. And attackers understand that math way better than most boards do.
Now the part that should piss you off
I’ve traveled to 88 countries solo so when plan A veers and you’ve got to pivot or run to execute plans B and C, all this convenience tech feels like a critical element to literally get home. So, let’s follow the loop a traveler actually lives.
The airport collects your data so you can get online. Public WiFi is an untrusted network (for love of droids and robots, don’t use it without maniacally locking down your settings), so the right move is to run a VPN. Every security professional worth listening to will tell you exactly that.
So, you protect do the responsible thing to yourself. And guess what? Now a growing share of the internet treats you like a criminal for doing it. Major platforms run automated anti-abuse systems that read VPN traffic, proxy traffic, data-center IPs, and quick location changes as danger. Because that’s a tell-tale sign of bot behavior, fraud, and/or ban evasion. When you log in through a VPN, the machine scores you as a probable bad actor.
In 2026, Meta deleted millions of accounts and real people were caught up in the sweep, with users reporting permanent bans and no clear path back. Age-verification laws across Australia, several US states, and the UK pushed privacy-conscious people toward VPNs, and the platforms complying with those same laws’ response was to unilaterally restrict access on the other side of the door.
Now, let’s sit with that path.
The airport harvests your email to hand you WiFi, then loses it.
The network is risky, so you reach for the one tool built to shield you.
So, then the platform sees that tool and locks YOU out.
And here, my friends, is what makes this worse, of course, in my opinion. Not one person at these companies wrote a policy that says punish privacy. Nope, the automation produced that outcome on its own. Someone determined a blunt signal, unfamiliar IP equals likely trouble, and then let that run at scale. So, now, the system penalizes the exact secure behavior we’ve been begging people to adopt when using airport WiFi and/or public WiFi. That’s an automated harm nobody chose, and nobody is quick enough to unwind by hand.
This is the fundamentals argument I keep making
You can’t automate your way out of a weak foundation. This is a hard no. Do not pass go and do not collect your $200.
Automation just magnifies and multiplies the foundation (good or bad) that you are already standing on, and it does it at machine speed. Build the floor to hold, and speed becomes the advantage you wanted. Skip that work or vibe code your way past the fundamentals and the cracks propagate faster than any human team can chase them.
The Manchester breach, the Collins Aerospace outage, and the VPN mess share one root. Systems are running faster than the judgment meant to govern them.
Every board in aviation wants to slap AI onto operations, service, security, and marketing. Ok, that ambition sounds reasonable, but the order of operations is the whole game. You gotta prove (i.e., trust and verify) that the floor holds, and then and only then add the machine that runs across it.
8.7 million people did absolutely nothing wrong. They just wanted WiFi.
What to do!
Here are two checklists. One for the people running the systems and one for the people using them.
The Fundamentals Floor: answer these before you automate anything
- Minimize. Collect only what the service genuinely needs. A WiFi login does not need a phone number. Data you never gathered cannot leak.
- Segment. Wall the customer-convenience layer off from anything of value. When parking falls, it should take nothing else with it.
- Govern identity, human and machine. Every service account, API key, and token is a door. Manage the machine identities with the same rigor you apply to employees, because attackers love the ones you forgot.
- Detect fast. Measure your dwell time and drive it down. Days of silence is a monitoring failure you can fix before it becomes a headline.
- Contain the blast. Map what falls if any single system falls. Rehearse the answer before an attacker writes it for you.
Score all five honestly. Don’t score to make yourself feel good. If you can’t emphatically answer these five with, we do this and know who (named person/team) does it, can reference it, then that’s a verifiable fact. Anything else is emotional soothing conjecture. Until they hold, you have business messing with agents and for the love of all things Dolly Parton, no agent goes near production. An autonomous system laid over gaps like these does one thing well: it scales all the gaps.
Protect yourself at the airport
- Run a VPN on public WiFi. If a platform punishes you for it, that failure belongs to the platform, and it deserves a loud complaint. Don’t acquiesce and turn off VPN.
- Hand over the least amount of your data you can. Keep a throwaway or masked email for signups.
- Check the network name before you connect. Evil-twin hotspots copy the real one letter for letter.
- Turn on two-factor authentication everywhere it’s offered.
- Treat any surprise email, text, or call claiming to be the airport as suspect. This breach just became fuel for very convincing phishing.
The fix for all of it starts in the same place. Fix the floor, then bring the bots.
Share this article
Related Articles
The Reskilling Illusion: When AI Transformation Means "You're Fired"
Oct 03, 2025