Security News

Extortion Group Claims Massive Data Theft from Manchester Airports Group

Security Week · 31 Aug 2026
Key Takeaway Regularly audit who has access to sensitive data and monitor for unusual large data transfers, since extortion groups increasingly steal information quietly before making public threats.

A cyber extortion group calling itself FulcrumSec has claimed responsibility for stealing more than 80 gigabytes of data from Manchester Airports Group, one of the UK's largest airport operators. According to reports, the group is threatening to publish the stolen data online if its demands are not met, a tactic increasingly common among extortion-focused threat actors who skip encryption-based ransomware and go straight to data theft and public leak threats.

This style of attack, often called 'extortion without encryption,' can be harder to detect because it doesn't necessarily disrupt IT systems the way traditional ransomware does. Instead, attackers rely on the reputational and regulatory damage of exposed data to pressure victims into paying. Details about how the breach occurred have not been confirmed, and Manchester Airports Group has not yet verified the extent of the claimed theft.

For Australian small businesses, this incident is a reminder that large organisations with mature security teams remain targets, and the same extortion tactics are increasingly used against smaller, less-defended businesses that hold valuable customer or partner data. Attackers often gain initial access through stolen credentials, phishing, or unpatched systems before quietly exfiltrating data over time.

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.