🔒MAG Exposed API Keys for 4 Years, Risking Customer Data
Exposed API keys put millions of customer records at risk
TL;DR
Manchester Airports Group (MAG) exposed API keys for four years, potentially compromising millions of customer records. The keys, found in JavaScript bundles, had read/write access to core Iterable endpoints, allowing for data deletion and manipulation.
Manchester Airports Group (MAG) exposed API keys in client-side JavaScript for four years, potentially compromising millions of customer records. These keys, which had read/write access to core Iterable endpoints, could be used to delete customer records and rewrite profiles. The vulnerability, which could have gone unnoticed by MAG's IT teams, was first seen in June and July 2022 and remained exposed until August 2026. MAG is continuing its investigation alongside the Information Commissioner's Office (ICO) and supporting the National Crime Agency with its inquiries. The incident highlights the importance of securing API keys and following best practices to prevent such exposures.

Key Points
MAG exposed API keys in client-side JavaScript for four years, potentially compromising millions of customer records.
The API keys were used to authorize server-side API operations, which Iterable's documentation explicitly warns against.
The keys had read/write access to core Iterable endpoints, allowing for data deletion and manipulation.
The vulnerability was first seen in June and July 2022 and remained exposed until August 2026.
MAG is continuing its investigation alongside the Information Commissioner's Office (ICO) and supporting the National Crime Agency with its inquiries.
Why It Matters
If you're managing customer data through Iterable or any similar service, this incident highlights the critical importance of securing API keys and following best practices to prevent such exposures. The risk of data breaches and unauthorized access is real and can go undetected for years.
Frequently Asked Questions
Why does this matter?
If you're managing customer data through Iterable or any similar service, this incident highlights the critical importance of securing API keys and following best practices to prevent such exposures. The risk of data breaches and unauthorized access is real and can go undetected for years.
What happened?
Manchester Airports Group (MAG) exposed API keys for four years, potentially compromising millions of customer records. The keys, found in JavaScript bundles, had read/write access to core Iterable endpoints, allowing for data deletion and manipulation.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,471 builders reading daily.