Security boffin claims airport group left API keys in client-side JavaScript for four years
- ID
- 22711
- Status
- summarized
- Published
- 09 Sep 2026, 7:14 PM
- Fetched
- 09 Sep 2026, 7:43 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/cyber-crime/2026/09/09/security-boffin-claims-airport-group-left-api-keys-in-client-side-javascript-for-four-years/5295192
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 7.5
- Created
- 09 Sep 2026, 7:44 PM
- Tags
- Audience
- developersvibe_coderssaas_founders
What happened
Security researcher Scott Helme confirmed FulcrumSec's claim that Manchester Airports Group (MAG) exposed overprivileged Iterable API keys in client-side JavaScript bundles across its three airport websites from June/July 2022 through August 2026, potentially compromising 8.8 million customer records. The keys were used to authorize server-side API operations directly from the browser—something Iterable's documentation explicitly warns against—and were overprivileged enough to enable mass data deletion. Helme used the Wayback Machine to verify the keys had been publicly retrievable for over four years.
Why it matters
If you ship any third-party API integration in a web frontend, audit whether credentials are embedded in JS bundles or proxied through your own backend—this incident shows the exact anti-pattern (client-side keys calling server-side APIs) persisted unnoticed for four years at a major organization. Check that keys are least-privileged and rotated, and verify your Iterable or similar marketing platform keys aren't exposed in your own bundles.
Discussion angle
How to systematically audit your own frontend bundles for leaked API keys, and why overprivileged service keys in client-side code are a systemic failure pattern that tooling should catch automatically.