Security boffin claims airport group left API keys in client-side JavaScript for four years
cyber-crime
Researcher believes overprivileged Iterable creds exposed 8.8M customer records – and could have enabled mass deletion
Security researcher Scott Helme says his analysis supports FulcrumSec's claim that Manchester Airports Group (MAG) exposed privileged API keys in client-side JavaScript.
Helme says he reached that conclusion after using information provided by the cyber extortion group to reconstruct how data belonging to roughly 8.8 million MAG customers was allegedly stolen last month.
The crooks behind the attack described MAG's security failure as "tragi-comical." They claimed MAG exposed overprivileged API keys for Iterable, a marketing automation platform, in front-end JavaScript served by the websites of MAG's three airports: Manchester, Stansted, and East Midlands.
Helme used the Internet Archive's Wayback Machine to retrieve older versions of the JavaScript and found that the three keys first appeared across the airport websites in June and July 2022. The same values remained exposed until August 2026, he said.
"Read the timeline the other way round and it's worse," said Helme. "Anyone who looked at that page source on any day between June 2022 and August 2026 could have taken the key. FulcrumSec just happen to be the ones who told us.
"There is no way to know, from the outside, who else did, and the honest answer is that MAG can't know either without going back through four years of Iterable API logs, if they even have four years of Iterable API logs."
The API keys were not embedded directly in the HTML, Helme explained, but anyone who examined the JavaScript bundles loaded by the sites could find them. This would explain how the vulnerability could go unnoticed by the airport's IT teams for over four years.
Helme says the browser-delivered code was using the keys to authorize server-side API operations – something Iterable's documentation explicitly warns against. The requests should instead have passed through MAG's own servers, where the credentials could be kept secret and access restricted.
MAG's alleged exposure of the credentials was not the only issue at play. The keys were vastly overprivileged for their intended job, which was to attribute page clicks to marketing emails, Helme said.
The keys had read/write access to core Iterable endpoints, giving anyone who obtained them the ability to access data such as customer profiles, parking and lounge bookings, and Fast Track purchases.
Helme said the structure and contents of the stolen data indicated that it had been exported from Iterable. He said he also found that the keys could access endpoints capable of deleting customer records and lists or rewriting profiles.
"There's no indication FulcrumSec did any of this, and I'm glad, but they could have just nuked everything from orbit and MAG would have been really screwed," said Helme. "For four whole years, the capability to delete Manchester Airports Group's database was a view-source away.
"This wasn't only a confidentiality exposure. It was a colossal integrity and availability exposure too, and MAG just got lucky. How do they now trust any of the data that remains in the database?"
When it disclosed the incident, MAG described the cyberattack as "sophisticated" and said it was "a hack, not a lapse."
The company declined to comment on Helme's conclusions. MAG is continuing its investigation alongside the Information Commissioner's Office (ICO) and supporting the National Crime Agency with its inquiries.
It is understood that MAG maintains it was the victim of a crime and disputes Helme's "no hacking required" characterization.
FulcrumSec released the company's data on September 2, a week after MAG confirmed it had refused to pay. According to the ICO, the group's extortion demand was lower than those typically made by cybercriminals. ®
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0
Comments (0)