Cyber Cookie mascotCyber Cookie
Menu ▾
← LatestIssue #81September 4, 2026

Ransom Refused, 8.8 Million Records Published

Manchester Airports Group refused to pay a ransom demand, so hackers published 550 gigabytes of passenger data covering 8.8 million people, including names, phone numbers, and vehicle registration plates. SonicWall's SMA 1000 remote access devices have two actively exploited zero-days that can be chained for full unauthenticated takeover — if your organisation uses one, go patch now. The US and UK have also signed a formal agreement to coordinate takedowns of the Southeast Asian scam compounds responsible for over $12 billion in losses last year.

Breach of the Day

Manchester Airports Group Refused to Pay — So Hackers Published Everything

Manchester Airports Group (MAG), which operates Manchester, London Stansted, and East Midlands airports, disclosed last week that hackers had breached systems belonging to a third-party database provider, according to SecurityWeek.

The attacker, an extortion group calling itself FulcrumSec, says it got in using admin keys that were left exposed inside the public-facing JavaScript code of each airport's website. Think of it like hiding your front door key under a welcome mat, then posting a photo of the mat online.

MAG declined to pay. FulcrumSec published roughly 550 gigabytes of data anyway.

Breach notification site HaveIBeenPwned parsed the dataset and confirmed approximately 8.8 million email addresses and phone numbers were exposed. Names, vehicle registration plates, postal regions, residential IP addresses, browser details, and purchase records for airport parking, lounges, and fast-track services were also included. The attackers additionally claim to have captured over 461,000 SMS messages and more than 108,000 unique UK vehicle registration plates.

MAG confirmed no airport operations were disrupted.

If you have ever used car parking, a lounge, or fast-track services at any of the three airports, or connected to their in-airport Wi-Fi, your details may be in this dataset.

What to do: Check your email at haveibeenpwned.com. If you are in the breach, be alert to phishing emails using your name and travel details to appear convincing. Do not click links in unsolicited messages referencing airport bookings.

Emerging Threats

Fake Merger and Acquisition Deals Are Being Used to Target Large Enterprises

Attackers are now running elaborate fake merger and acquisition scams against large enterprises, according to Dark Reading.

The mechanism here is social engineering (manipulating people into revealing information or taking action through deception rather than technical exploits). M&A processes are already high-pressure, involve unusual financial transfers, and regularly bring in unfamiliar external parties — which makes them ideal cover for fraud. Employees may receive convincing correspondence appearing to come from law firms, investment banks, or senior executives, pressuring them to share sensitive documents or authorise payments.

The full article was unavailable at time of writing, but the pattern is well-established: urgency plus authority plus an unfamiliar process equals a dangerous combination.

What to do: If your organisation is involved in any M&A activity, verify all payment requests and document sharing through a separate, confirmed communication channel before acting.

Vulnerability Watch

CVE-2026-83548 — SonicWall SMA 1000 (versions 12.4.3-03453 / 12.5.0-02835 and older)

What SonicWall SMA 1000 is: A remote access gateway used by organisations to let employees connect securely to corporate networks from outside the office.

What it is: CVE-2026-83548 is a pre-authentication SSRF (server-side request forgery — where an attacker tricks the server into making requests on their behalf) flaw in the user-facing portal. No login is required to trigger it.

Who's at risk: Any organisation running an affected SMA 1000 appliance exposed to the internet. Models 6210, 7210, and 8200v on the affected firmware versions are vulnerable. Exploitation is confirmed and ongoing.

CVSS: 10.0 (Critical — patch today, before anything else).

Root cause: The flaw exists because the appliance does not properly restrict which internal resources the user-facing portal is permitted to reach. An unintended alternate access path allows requests to bypass the controls that should keep unauthenticated users out of sensitive functionality.

Attack vector: An unauthenticated attacker sends a crafted request to the public-facing portal. The appliance processes it without checking whether the sender has any credentials, giving the attacker access to sensitive internal functions. When chained with CVE-2026-83549 (a separate authenticated OS command injection flaw in the admin console), the result is full remote code execution on a device sitting directly on the internet.

Detection strategies: Check for unexpected or repeated requests to internal portal endpoints from external IPs. Review admin console access logs for activity from unrecognised accounts. Look for anomalous outbound connections from the appliance itself.

Recommended actions:

  1. Upgrade immediately to firmware 12.4.3-03526 or 12.5.0-02952.
  2. If indicators of compromise are found, re-image hardware appliances or re-deploy virtual ones.
  3. Reset all user and administrator passwords and TOTP tokens after patching.
CVE-2026-83548criticalCVSS 10

SonicWall SMA 1000 (versions 12.4.3-03453 / 12.5.0-02835 and older)

A remote access gateway used by organisations to let employees connect securely to corporate networks from outside the office.

Defender's Corner

Check Whether Your Details Are Already Out There

HaveIBeenPwned is a free service that tells you whether your email address or phone number has appeared in a known data breach. It is run by respected security researcher Troy Hunt and is widely trusted.

With 8.8 million records from the Manchester Airports Group breach now in its database, this is a good moment to check. Go to haveibeenpwned.com, enter your email address, and see which breaches it appears in. You can also set up free alerts so you are notified automatically if your details appear in future leaks.

If your email is listed, update passwords on affected accounts and switch on two-factor authentication (a second verification step beyond your password) wherever it is offered.

Compliance Pulse

US and UK Sign Formal Agreement to Coordinate Scam Compound Takedowns

The United States Department of Justice and the UK's National Crime Agency signed a memorandum of understanding this week committing both countries to parallel investigations and shared intelligence on the organised crime networks running Southeast Asian scam compounds, according to The Record. More than $12 billion was stolen from Americans alone last year through these schemes. The two agencies have already identified overlapping cases and plan a joint disruption event in London in October.

Somewhere in Southeast Asia, a scam compound operator is having a worse Thursday than you.

Cyber Cookie is AI-assisted. Always verify critical information with official sources before acting.