ICO fines & breach roundup — 2 September 2026
A plain-English look at recent UK Information Commissioner's Office (ICO) enforcement and notable data-protection news — who was penalised, why, and what a small business should learn from it. The pattern is consistent and the lessons are cheap to act on.
1. Manchester Airports Group tells 8.7 million customers their data was taken — reportedly via a key left in a public web page
Manchester Airports Group (MAG), which runs Manchester, London Stansted and East Midlands airports, confirmed on 27 August 2026 that an unauthorised third party had accessed data belonging to around 8.7 million customers, and began emailing them. The affected records relate to car park, lounge and Fast Track bookings and airport Wi-Fi registrations, and include email addresses, phone numbers, postcodes and vehicle registration numbers. MAG says neither it nor the affected system held bank or payment card details, that aviation security and airport operations were unaffected, and that it has notified the ICO, the National Cyber Security Centre and law enforcement. MAG told the BBC a ransom was demanded and that it refused to pay. An extortion group calling itself FulcrumSec has claimed responsibility and says it took around 86GB of data; that claim, and its account of how, are the group's own and have not been confirmed by MAG. What makes the claimed method worth reading is how mundane it is: FulcrumSec says it did not break into anything, but simply found an API credential for Iterable — the third-party marketing and customer-engagement platform holding the data — sitting in the JavaScript that MAG's own website sends to every visitor's browser, and used it to query the platform directly. No ICO outcome has been published; the regulator is at the "assessing what we've been told" stage, which is where every fine in this series started.
What your business should learn: Anything your website sends to a visitor's browser is public, including the code — anyone can press F12, read your page source, and search it. If your site connects to a mailing-list tool, a booking system, a chat widget or an analytics platform, ask whoever built it a direct question: is any key, token or password for those services present in the front-end code? It is a five-minute check and the fix (move the call to your server, or issue the platform a key that can only do the one narrow thing the page needs) costs a developer an hour. Then ask the second question, which is the one this case really turns on: your customer data probably lives in a supplier's platform rather than on your own systems, so who holds the keys to it, how many people have them, and when were they last changed?
2. Elderly Aids Ltd fined £190,000 for making 758,053 nuisance calls — while selling nuisance-call blockers
The ICO fined Elderly Aids Ltd £190,000 in late August 2026 for making 758,053 unsolicited marketing calls between May 2024 and February 2025 to people registered with the Telephone Preference Service (TPS) — the free register that tells companies a number must not be cold-called. The company was selling call-blocking devices marketed at protecting elderly people from exactly this kind of call, charging a reported £139 sign-up fee plus £6.99 a month. Complainants described callers who were aggressive, misleading and often would not say who they were; one said their father was pressured into signing up. Under the Privacy and Electronic Communications Regulations (PECR), a live marketing call to a TPS-registered number is unlawful unless that person has specifically told your company they are happy to be called — and the ICO found none of the 758,053 had. The regulator described a complete disregard for the rules, which is the language it uses when the failure looks deliberate rather than sloppy.
What your business should learn: If you make marketing phone calls to anyone, you must screen your list against the TPS before you dial, and you must be able to show you did — the TPS licence is a modest annual cost and screening is the entire compliance obligation for most small firms. Two practical habits make the difference: keep the dated screening file for every campaign, because "we thought the list was clean" is not a defence when the ICO asks; and if you buy lists or use a call centre, put in writing who is responsible for TPS screening and consent records, because the fine lands on the business whose product is being sold, not on the agency that dialled. The same logic applies to texts and emails, where the rule is consent rather than a register — and note that PECR penalties now reach far higher than the old £500,000 ceiling.
Sources
- Infosecurity Magazine — Manchester Airports Group Hit by Cyber Incident
- IT Pro — Manchester Airports Group attack: everything we know so far as 8.7 million customers impacted
- BleepingComputer — FulcrumSec claims Manchester Airports hack, theft of 86GB of data
- SecurityWeek — Extortion Group Claims Manchester Airports Group Data Breach
- Security Affairs — Extortion group FulcrumSec claims 86GB Manchester Airports Group data theft
- TechNadu — FulcrumSec claims the theft of 86GB via exposed Iterable API credentials
- ICO — ICO hits company selling call blockers with £190k fine for nuisance calls
- The Register — Nuisance-call blocker fined £190k for being a nuisance caller
- Yorkshire Post — Nuisance call blocking company fined £190,000 for making 750,000 nuisance calls itself