”
Supporting FulcrumSec’s allegations, security researcher Scott Helme asserts that Manchester Airports Group (MAG) left highly sensitive API keys embedded within client-side JavaScript, creating a critical security gap for almost four years.
Security researcher Scott Helme supports FulcrumSec’s claims, revealing that Manchester Airports Group (MAG) failed to secure critical API keys by embedding them directly into client-side JavaScript during development. Based on intelligence gathered through collaboration with the cyber extortion group responsible for the breach, Helme demonstrates how the credentials—used to interact with the marketing platform Iterable—resided within front-end bundles on the websites of Manchester, Stansted, and East Midlands airports.
After analyzing archived versions of the site code using the Internet Archive’s Wayback Machine, Helme determined that these overprivileged keys first appeared online in June or July 2022 and remained public until August 2026. He noted that the persistence of these keys across six years suggests a fundamental misconfiguration that went unnoticed for far longer than typical red-team assessments recommend.
“The timeline is clear,” Helme stated. “Anyone who examined the page source on any day between 2022 and 2026 could have extracted the key. FulcrumSec correctly identified our exposure.” Crucially, he explained that the keys were not hard-coded into static HTML; rather, they were delivered dynamically via JavaScript. This allowed attackers to execute unauthorized commands against the underlying Iterable platform before reaching the proper authentication gateways.
“The vulnerability stemmed from placing administrative-level data in public view,” Helme elaborated. “These keys carried Read/Write permissions to core endpoints, effectively granting anyone who caught them access to customer profiles, parking and lounge allocations, and transaction histories.”
He emphasized that while MAG characterizes the incident as a sophisticated ‘crash’ rather than a deliberate compromise, the implications are severe. Without restrictions on where API keys are executed, the organization held a blueprint for complete database eradication. Helme warns that beyond the confidentiality breach affecting millions of travelers, the capacity to permanently delete records posed a catastrophic risk to user trust.
MAG has cooperated with the Information Commissioner’s Office and the National Crime Agency, though it denies any coordination with Helme. Meanwhile, the cyber-extortion group, which demanded money before releasing data, maintained that it lacked the necessary technical leverage, despite their successful exploitation of public-facing code. The incident underscores the dangers of relying on client-side delivery for high-privilege credentials.
[/blockquote]Also Read
- Live Eel Punctures Fisherman’s Colon After Rectal Entry
- Fairphone Gen 6+ Hits U.S. Market: In‑Depth Review of Eco‑Friendly Design, Display, Battery, Camera, and Software Features
- Former DeepMind Engineers Launch Startup to Streamline Fusion Reactor Control
- Sony September 2026 Deal Roundup: Up to 45% Off Headphones, Cameras, TVs, and Gaming Gear


