Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

Manchester Airports Group exposed over-privileged API keys in website code for four years

Security researcher Scott Helme says Manchester Airports Group left highly privileged Iterable API keys in client-side JavaScript from mid-2022 until August 2026, potentially exposing data of about 8.8 million customers.

Scott Helme, a security analyst, traced three Iterable API keys that were embedded in the JavaScript delivered by Manchester Airports Group’s three airport sites—Manchester, Stansted and East Midlands—from June/July 2022 until August 2026. The keys were over-privileged, granting read/write access to core Iterable endpoints, which could reveal or delete customer profiles, parking, lounge bookings and Fast Track purchases.

Although the keys were not directly visible in the HTML, they were discoverable in the client-side code, violating Iterable’s guidance that such credentials remain server-side. Helme believes the exposure allowed the theft of data belonging to roughly 8.8 million MAG customers, as indicated by the data released by the extortion group. MAG described the breach as a “sophisticated hack” and is working with the Information Commissioner’s Office and the National Crime Agency, while denying that the breach required any hacking on the part of the attackers. FulcrumSec, the security firm that first reported the issue, released the compromised data on September 2 after MAG refused to pay the ransom.

Why it matters

Exposed API keys could let attackers view, alter or erase millions of travel records, threatening privacy and service reliability.

In this story

API keysclient-side JavaScriptdata breach8.8 million recordsIterableManchester Airports Groupsecurity vulnerabilitycustomer data exposure
Get the beta ↗