<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>News Agent — Transportation &amp; Logistics</title><link>/industries/transport-logistics/</link><description>Cyber threat intelligence for the Transportation &amp; Logistics industry — daily-brief items tagged to this slice.</description><item><title>Manchester Airports Group data actually published Sep 8 after MAG refused FulcrumSec&#x27;s ransom demand</title><link>/briefings/2026/09/09/2026-09-09/</link><guid isPermaLink="false">2026-09-09-Manchester Airports Group data actually published Sep 8 afte</guid><pubDate>Wed, 09 Sep 2026 06:00:00 +0000</pubDate><description>Manchester Airports Group data actually published Sep 8 after MAG refused FulcrumSec&#x27;s ransom demand — confirms the 8.8M-person scope first reported Sep 4. Roughly 550GB went up, including car-park, lounge and Fast Track booking records and in-terminal Wi-Fi sign-ups across Manchester, Stansted and East Midlands; MAG has confirmed operations were unaffected. No new tracker entry (already logged Sep 4) — this is confirmation the threat was executed, not a new incident. SecurityWeek [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>Manchester Airports Group / FulcrumSec</title><link>/briefings/2026/09/05/2026-09-05/</link><guid isPermaLink="false">2026-09-05-Manchester Airports Group / FulcrumSec</guid><pubDate>Sat, 05 Sep 2026 06:00:00 +0000</pubDate><description>Manchester Airports Group / FulcrumSec — 8.8M traveller records published after ransom refusal; API credentials left in public JavaScript — FulcrumSec published roughly 550GB of uncompressed data (86GB compressed) on September 4 after Manchester Airports Group (MAG) declined to pay its ransom demand. The exfiltrated dataset covers parking bookings, lounge access, Fast Track purchases, and Wi-Fi sign-ups at three UK airports (Manchester, London Stansted, East Midlands), and contains email addresses, phone numbers, vehicle registrations, and postcodes for approximately 8.8 million people. Payment-card data was not accessed. Root cause: FulcrumSec extracted 86GB from MAG&#x27;s Iterable marketing-automation platform using API credentials the group found embedded in publicly accessible JavaScript code on each airport&#x27;s website — no network intrusion required. MAG disclosed the incident on August 27; FulcrumSec claimed responsibility September 1 and published September 4. UK ICO and relevant authorities have been notified. SecurityWeek · BleepingComputer · Infosecurity Magazine [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>FulcrumSec</title><link>/briefings/2026/09/05/2026-09-05/</link><guid isPermaLink="false">2026-09-05-FulcrumSec</guid><pubDate>Sat, 05 Sep 2026 06:00:00 +0000</pubDate><description>FulcrumSec — MAG data published Sep 4; credential-in-JavaScript MO is repeatable at scale — FulcrumSec&#x27;s attack against Manchester Airports Group required no network intrusion: the group harvested Iterable API credentials from publicly accessible JavaScript code. This MO — harvesting keys from frontend JS or CDN-hosted bundles — requires no exploit, is undetectable by traditional network monitoring, and applies to any organisation whose marketing/analytics platform is configured with client-side credentials. FulcrumSec is now confirmed as a distinct extortion actor with at least one major publication. BleepingComputer · SecurityAffairs [🌐 THREAT ACTOR &amp; CAMPAIGN ACTIVITY]</description></item><item><title>The FulcrumSec/MAG attack is the proof-of-concept that credential harvesting from public JavaScript is now a mass-scale extortion vector aga</title><link>/briefings/2026/09/05/2026-09-05/</link><guid isPermaLink="false">2026-09-05-The FulcrumSec/MAG attack is the proof-of-concept that crede</guid><pubDate>Sat, 05 Sep 2026 06:00:00 +0000</pubDate><description>The FulcrumSec/MAG attack is the proof-of-concept that credential harvesting from public JavaScript is now a mass-scale extortion vector against large consumer-data platforms — no intrusion required, audit trails are minimal, and the liability is proportional to data volume, not attack sophistication. Manchester Airports Group&#x27;s Iterable API keys were embedded in publicly visible JavaScript — a configuration error that requires no exploit to weaponise, no network footprint to generate, and no EDR to evade. The result was 8.8 million records and the full extortion cycle in one operation. The attack pattern scales: any organisation with a marketing-automation or customer-data platform configured with client-side credentials is a structural equivalent target. For a PE portfolio holder, the risk is not in whether the company ran a secure network — it is in whether its customer-data platforms were audited for exposed credentials at the application layer. BleepingComputer · SecurityWeek [🌍 GEOPOLITICS]</description></item></channel></rss>
