A recent investigation by cybersecurity researcher Scott Helme has uncovered a significant security lapse at Manchester Airports Group (MAG), which allegedly left privileged API keys exposed in client-side JavaScript for over four years. This exposure is believed to have compromised the data of approximately 8.8 million customers.
Details of the Exposure
Helme’s analysis supports claims made by the cyber extortion group FulcrumSec, which highlighted MAG’s failure to secure API keys associated with the marketing automation platform Iterable. The keys were embedded in the front-end JavaScript of MAG’s airport websites—specifically those for Manchester, Stansted, and East Midlands—and were accessible from June 2022 until August 2026.
Implications of Overprivileged Access
The exposed API keys provided read/write access to critical Iterable endpoints, allowing unauthorized access to sensitive customer data, including profiles and bookings. Helme noted that the keys could have enabled malicious actors to delete customer records or alter profiles, presenting a significant risk to MAG’s data integrity. He remarked, “For four whole years, the capability to delete Manchester Airports Group’s database was a view-source away.” This vulnerability raises questions about the reliability of the data MAG currently holds.
MAG’s Response and Ongoing Investigations
In response to the incident, MAG characterized the cyberattack as a “sophisticated” hack rather than a security lapse, a claim they continue to uphold. The company is currently cooperating with the Information Commissioner’s Office (ICO) and the National Crime Agency to investigate the breach. However, MAG has declined to comment on Helme’s findings, which suggest that the exposure did not require hacking skills to exploit.
Future Considerations for Cybersecurity
The incident underscores the critical need for organizations to implement robust security measures, particularly regarding API management and data exposure. Helme’s findings indicate that MAG’s oversight could have led to severe consequences had malicious actors chosen to exploit the vulnerability. As the investigation unfolds, the implications for MAG and the broader industry regarding data security practices will be closely monitored.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








