The Cyber Threat Intelligence Briefing is a weekly round-up of the latest cybersecurity news, trends and indicators, curated by our CISO, Nick Harris. Here’s our pick of the top stories, and why you should care
FulcrumSec claims responsibility for Manchester Airports Group data breach
Manchester Airports Group (MAG) confirmed a data breach on 27 August impacting 8.7 million customers. The threat actor claims it exfiltrated 86GB, including nearly 200,000 records tied to upcoming travel during the remainder of 2026. This contained dates, times and booking information linked to personally identifiable information (PII). MAG confirmed that data from car park, lounge, Fast Track bookings, and in-airport Wi-Fi registrations had been accessed, with email addresses, phone numbers, vehicle registrations, and postcodes among the compromised fields. No payment card or banking data were exposed.
Initially, MAG refused a ransom demand, but this appears to have led FulcrumSec, the threat actor claiming responsibility, to publish the dataset. They have apparently since deleted the most sensitive data, citing the harm caused by the Vastaamo incident.
How did it happen?
The group claimed to have found airport-specific API credentials for Iterable, a third-party marketing and customer engagement platform, embedded in client-side JavaScript on the MAG website. Any visitor with a browser’s developer tools open could have read those credentials without logging in or triggering any network anomaly. Once inside Iterable with high-privilege API access, the attacker could enumerate and export the marketing platform’s customer database without touching MAG’s core airport systems at all.
FulcrumSec is a financially motivated extortion group, previously known as The Threat Thespians, that emerged in late 2025 and was responsible for 23 recorded attacks in May 2026 alone. Other known victims include Novo Nordisk, Arup Group, and LexisNexis. Researchers at Sysdig note the group targets largely cloud-native businesses, exploiting hardcoded credentials, unpatched applications, or misconfigured storage buckets.
An ICO inquiry is widely expected given the scale of the customer base. Phishing campaigns referencing MAG car park, lounge, or Fast Track bookings are likely to spike in the coming weeks as opportunistic actors piggyback on the publicity.
This boils down to another third-party risk, and an example of what happens if an organisation doesn’t negotiate with its extorters.
Spring ring: Microsoft Teams vishing campaign targets enterprise domain controllers
Palo Alto Networks’ Unit 42 has uncovered a new vishing campaign featuring external Microsoft Teams accounts masquerading as IT help desk personnel. Detailed in a new report, the campaign targeted more than 150 employees across at least 10 companies in multiple industries.
The Spring Ring campaign weaponises what appears to be a routine IT support conversation into a pathway for domain-level compromise. Then, rather than delivering malicious links in chat, attackers initiate a voice phishing call during which they coerce victims into executing remote monitoring and management (RMM) tools or custom malware. In a more advanced variant, the attack escalates from a vishing call to a full NTLM relay attack targeting the organisation’s domain controller.
The geeky bit
The attack begins with a Microsoft Teams chat from an external account operating from a convincing “onmicrosoft.com” subdomain (e.g. ithelp@InternalSystemsDaily.onmicrosoft.com or ithelpdesk@CertifiedUpdateNetwork.onmicrosoft.com). Attackers exploit Teams’ default “Chat with Anyone” feature to initiate direct contact with targets outside their organisation. A voice call follows almost immediately.
Unit 42 observed two distinct campaign variants:
- The attacker walks the employee through launching Quick Assist or downloading a third-party RMM tool, then downloads an obfuscated PowerShell-based remote access Trojan (RAT) from an attacker-controlled domain. The RAT disables AMSI via the amsiInitFailed flag before beaconing out to download further payloads.
- The attacker directs the victim to a cloud-hosted executable tailored to their organisation, even including the victim’s name in the S3 bucket URL. The malware spawns persistence copies, and launches a hidden headless instance of Microsoft Edge to sideload a malicious browser extension. Then it uses Python to initiate SMB scanning and an NTLM relay attack via the PetitPotam exploit against the organisation’s domain controller.
Protections include restricting unsolicited external chats in Teams and allowlisting RMM tools rather than permitting on demand.
Teams-based phishing alerts rose by 41% between October 2025 and March 2026 according to KnowBe4. By the first four months of 2026 they represented 42% of all phishing alerts in Cortex telemetry, up from 30% in the preceding four months.
This is an example of how humans can bypass CISO investments in email security controls. Even with good controls, attackers can find the weak link.
AI-assisted intrusion: important nuance behind the headlines
An investigation into an AI-assisted cyber-attack by Unit 42 describes a human attacker using frontier AI agents to breach an enterprise network in under 10 hours. They reportedly told Unit 42 that they leveraged AI models and attack-specific agentic frameworks. They also directed the AI agent to produce an 80-page technical audit of the victim’s security posture, left behind as a pressure mechanism.
Here’s what we know:
- After the report was first published on September 2, Unit 42 had to update the article the following day to clarify it was an intrusion, not ransomware (no encryption of systems). That is worth noting when considering how this incident has been characterised in the press. As is the less headline-grabbing fact that the attacker who handled the AI execution was human
- We have to consider the “AI attack” could be serving the interests of Palo Alto, as a security vendor. Notably, there are strongly suggestive points, but not definitive proof, of fully autonomous operation
- There is no mention of token count, so we don’t know what it cost. It may be low if the threat actor was simply vibe coding their tooling
- The claim that the attack took “less than 10 hours” is used to imply autonomous execution. But a skilled solo human operator working a well-prepared toolkit against a network with hardcoded credentials sitting in repos could plausibly move that fast
- There is no description of security maturity. It says the attack succeeded “without the need for a novel zero-day or super elite tradecraft”. This could mean the victim was reasonably secured but AI made the attacker efficient enough to find ordinary weaknesses faster. However, several details suggest the victim had significant pre-existing hygiene problems: hardcoded tokens and service passwords sitting in code repositories, a secrets management system reachable via those exposed credentials, and CI/CD pipelines with insufficient controls. However, branch protection did stop the Terraform backdoor attempt, which is a point in the victim’s favour
It’s the speed, not sophistication, that is the takeaway. This is consistent with OpenAI’s Collective Cyberdefense initiative from a few weeks ago.
UK Cyber Security and Resilience Bill: where it stands and what it means
The cybersecurity minister has rejected a proposed amendment that would have brought AI vendors and frontier model developers directly into scope of the Cyber Security and Resilience Bill. Under the amendment, they would have faced NIS-style security obligations, incident reporting duties, and potential fines as operators of essential services and MSPs. Baroness Lloyd of Effra argued that regulating AI vendors through this bill would not prevent hostile actors from misusing their products.
Industry had already pushed back, arguing that it creates a structural mismatch: users are being held accountable for risks in systems they did not design and cannot fully audit. Whether the final text shifts more responsibility toward vendors will be one to watch as the bill progresses, as will the suggestion of requiring AI kill-switches.
If you are new to this, the UK’s Cyber Security and Resilience (Network and Information Systems) Bill is now in its Lords Committee Stage with a Third Reading to follow. It’s the biggest overhaul of UK cyber regulation since the NIS Regulations 2018. Royal Assent is expected in late 2026. Substantive impact is not expected until around 2028, but it will directly affect how IT service providers and CNI providers operate.
The bill introduces a 24-hour initial incident reporting requirement and fines of up to £17m or 4% of global turnover for the most serious failures. It also gives the secretary of state broad powers to designate additional sectors and entities through secondary legislation, which could make the eventual scope wider than the current bill suggests.
It will likely only be around a year from January when the bill takes effect. Even so, the scope is smaller than NIS2 and the requirements less onerous.