Skip to content
theregister·

🔒MAG Exposed API Keys for 4 Years, Risking Customer Data

Exposed API keys put millions of customer records at risk

TL;DR

Manchester Airports Group (MAG) exposed API keys for four years, potentially compromising millions of customer records. The keys, found in JavaScript bundles, had read/write access to core Iterable endpoints, allowing for data deletion and manipulation.

Manchester Airports Group (MAG) exposed API keys in client-side JavaScript for four years, potentially compromising millions of customer records. These keys, which had read/write access to core Iterable endpoints, could be used to delete customer records and rewrite profiles. The vulnerability, which could have gone unnoticed by MAG's IT teams, was first seen in June and July 2022 and remained exposed until August 2026. MAG is continuing its investigation alongside the Information Commissioner's Office (ICO) and supporting the National Crime Agency with its inquiries. The incident highlights the importance of securing API keys and following best practices to prevent such exposures.

MAG Exposed API Keys for 4 Years, Risking Customer Data — theregister

Key Points

1

MAG exposed API keys in client-side JavaScript for four years, potentially compromising millions of customer records.

2

The API keys were used to authorize server-side API operations, which Iterable's documentation explicitly warns against.

3

The keys had read/write access to core Iterable endpoints, allowing for data deletion and manipulation.

4

The vulnerability was first seen in June and July 2022 and remained exposed until August 2026.

5

MAG is continuing its investigation alongside the Information Commissioner's Office (ICO) and supporting the National Crime Agency with its inquiries.

Why It Matters

If you're managing customer data through Iterable or any similar service, this incident highlights the critical importance of securing API keys and following best practices to prevent such exposures. The risk of data breaches and unauthorized access is real and can go undetected for years.

api keysdata securitycustomer dataiterablemanchester airports group

Frequently Asked Questions

Why does this matter?

If you're managing customer data through Iterable or any similar service, this incident highlights the critical importance of securing API keys and following best practices to prevent such exposures. The risk of data breaches and unauthorized access is real and can go undetected for years.

What happened?

Manchester Airports Group (MAG) exposed API keys for four years, potentially compromising millions of customer records. The keys, found in JavaScript bundles, had read/write access to core Iterable endpoints, allowing for data deletion and manipulation.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,471 builders reading daily.

Also get