AI Weekly Malaysia

Back to items Summaries

Security boffin claims airport group left API keys in client-side JavaScript for four years

ID
22711
Status
summarized
Published
09 Sep 2026, 7:14 PM
Fetched
09 Sep 2026, 7:43 PM
Provider
The Register
Category
technology
Original URL
https://www.theregister.com/cyber-crime/2026/09/09/security-boffin-claims-airport-group-left-api-keys-in-client-side-javascript-for-four-years/5295192
Source URL
https://www.theregister.com/headlines.atom

Summary

Score
7.5
Created
09 Sep 2026, 7:44 PM
Tags
Audience
developersvibe_coderssaas_founders

What happened

Security researcher Scott Helme confirmed FulcrumSec's claim that Manchester Airports Group (MAG) exposed overprivileged Iterable API keys in client-side JavaScript bundles across its three airport websites from June/July 2022 through August 2026, potentially compromising 8.8 million customer records. The keys were used to authorize server-side API operations directly from the browser—something Iterable's documentation explicitly warns against—and were overprivileged enough to enable mass data deletion. Helme used the Wayback Machine to verify the keys had been publicly retrievable for over four years.

Why it matters

If you ship any third-party API integration in a web frontend, audit whether credentials are embedded in JS bundles or proxied through your own backend—this incident shows the exact anti-pattern (client-side keys calling server-side APIs) persisted unnoticed for four years at a major organization. Check that keys are least-privileged and rotated, and verify your Iterable or similar marketing platform keys aren't exposed in your own bundles.

Discussion angle

How to systematically audit your own frontend bundles for leaked API keys, and why overprivileged service keys in client-side code are a systemic failure pattern that tooling should catch automatically.

Top