{
  "id": 6415897,
  "title": "Security boffin claims airport group left API keys in client-side JavaScript for four years",
  "url": "https://urgent.news/2026/09/09/security-boffin-claims-airport-group-left-api-keys-in-client-side-6415897",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-09T11:14:00.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/cyber-crime/2026/09/09/security-boffin-claims-airport-group-left-api-keys-in-client-side-javascript-for-four-years/5295192"
  },
  "original_language": "en",
  "account": "Security analyst Scott Helme has corroborated FulcrumSec's assertion that Manchester Airports Group (MAG) inadvertently exposed privileged API keys in client-side JavaScript for a span of four years. By leveraging data from the cyber extortion group, Helme was able to piece together the incident and ascertain the extent of MAG's security lapse. The cybercriminals described MAG's mishap as \"tragical,\" citing MAG's failure to properly secure overprivileged API keys for Iterable, a marketing automation platform. The keys were embedded within JavaScript files served by MAG's websites for Manchester, Stansted, and East Midlands airports, and remained exposed from June 2022 to August 2026. This lapse allowed anyone who accessed the page source during this period to obtain the keys. Helme noted that the legitimate approach would have been to route requests through MAG's servers, safeguarding the credentials and restricting access. The stolen keys possessed extensive permissions, enabling the attackers to manipulate customer data, such as profiles, bookings, and purchases. MAG's response to the incident has been met with skepticism, as the company maintains that it was the victim of a crime, not a lapse in security.",
  "summary": "Researcher believes overprivileged Iterable creds exposed 8.8M customer records – and could have enabled mass deletion",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "Security boffin claims airport group left API keys in client-side JavaScript for four years",
        "url": "https://urgent.news/2026/09/09/security-boffin-claims-airport-group-left-api-keys-in-client-side",
        "published": "2026-09-09T11:14:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}