Security News

8.8 Million Records Exposed After Airport Group Refuses Ransom Demand

Security Week · 4 Sept 2026
Key Takeaway Regularly audit where administrative credentials and access keys are stored and used, and ensure none are exposed in public repositories, unsecured servers, or shared documents.

Manchester Airports Group (MAG) has had personal data belonging to an estimated 8.8 million people published online after refusing to pay a ransom to attackers. The hacker group behind the breach released approximately 550GB of stolen data, claiming the incident followed MAG's decision not to meet their financial demands.

According to the attackers, initial access was gained through exposed administrative keys — credentials that should have been kept private but were apparently accessible, allowing unauthorised entry into MAG's systems. This type of exposure is a common and preventable weakness, often resulting from misconfigured cloud storage, leaked credentials in code repositories, or poor secrets management practices.

This incident highlights a growing trend: ransomware and extortion groups increasingly leak stolen data publicly when victims refuse to pay, turning a security breach into a lasting privacy and reputational crisis. For businesses of any size, the exposure of administrative credentials can provide attackers with a direct path to sensitive systems, bypassing many other security controls entirely.

data breach ransomware credential security Manchester Airports Group incident response

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.