Manchester Airports Group reportedly told a ransomware crew no. Then roughly 550GB covering 8.8 million people showed up on a leak site anyway. Executives will talk about payment policy. Your cybersecurity team should talk about the group’s claimed entry path: exposed admin keys. A refused invoice does not revoke a live secret. It just decides who publishes first.

Keys don’t read your board minutes.

If you run airports, courts, hospitals, or any other population-scale records shop, this week is a secrets problem with a ransom headline glued on. Treat it like theater and you’ll brief the same slide after the next dump. Treat it like key hygiene, vendor blast radius, and hour-scale incident response, and you might still have a bad week. You’ll have a shorter one.

Illustration of fraud and cybercrime themes related to large-scale data leaks
Leak-site theater gets the quotes. Exposed admin credentials decide whether 8.8 million records ever leave.

Payment policy doesn’t revoke a live key

Ransom refusal is a governance choice. You can defend it. Plenty of teams should. What you can’t do is confuse that choice with containment. Once an admin key, cloud credential, or break-glass token is sitting where a scanner, a ticket attachment, or a forgotten automation user can eat it, the rest of the operation is logistics. Copy the store. Stage the archive. Wait for the “no.” Hit publish.

That’s a bad look for any operator that still files “secrets management” under the same queue as password resets. Admin keys are not a user inconvenience. They are remote root with a boring name. They skip the brute-force noise your lockout policy is tuned to catch. They often skip your firewall’s idea of a suspicious session because the call authenticates. To the identity plane, it looks like you.

So your threat detection has to assume valid secrets will be used invalidly. Impossible travel on the principal. First-time regions. Sudden enumeration of object stores. A quiet identity that never listed buckets until Tuesday at 02:14. If your threat-protection stack only lights up on malware hashes and known C2, the MAG-style path never trips a siren. It just looks like a script with a badge.

Researchers this week also described frontier AI agents compressing what used to be a two-week intrusion into something like ten hours. You do not need to buy the hype cycle to take the operational point. The window between “key is live” and “archive is gone” is no longer a comfortable sprint planning exercise. Rotation SLAs measured in days are a gift. Your cyber security program either shortens that loop or it narrates the dump after the fact.

C-Track is not “someone else’s incident”

While MAG was eating leak-site coverage, Thomson Reuters disclosed unauthorized activity in C-Track, the court case management platform run through its subsidiaries. Courts in at least 12 U.S. states, the U.S. Virgin Islands, and Canada sit on that stack. Sealed filings. Personal data. The kind of records people assume are protected by architecture and statute, not by a vendor’s shared tenancy and whoever holds the admin path into it.

Thomson Reuters headquarters building associated with the C-Track court records breach
Sealed court records on a vendor platform are still production data. Your IR runbook has to name that tenant.

Sealed does not mean segmented. If the case management plane can see the filing, so can a session that looks like an administrator. You already knew this in theory. You still let court IT, airport IT, and “the software company we contracted” live in three different risk registers with three different paging trees. Attackers do not honor that org chart.

Defense in depth here is ugly and specific. You need a mapped inventory of which records a vendor can export in one authenticated pull. You need contractual rights to logs you can actually query during incident response, not a PDF two weeks later. You need an assumption that their identity provider is now adjacent to yours. If MAG’s lesson is “don’t leave admin keys on the porch,” Thomson Reuters’ lesson is that the porch might belong to a company whose logo is on the login page.

This is still your problem when the press release says “subsidiaries” and “certain systems.” Passengers and litigants will not parse that sentence. Your board will, badly, unless you already have a vendor-compromise playbook that names the data classes, the notification clocks, and who is allowed to say “we don’t think it was us” before telemetry agrees.

Do this before the next dump hits a leak site

Skip the tabletop where everyone debates Bitcoin. Run the one where a valid admin key is already in someone else’s scripts. Immediate actions first. Then the boring loop that keeps you from repeating MAG with better letterhead.

  • Inventory every long-lived admin key, service principal, and break-glass user that can list or copy bulk records. Kill unused ones today. Put a human owner and an expiry on the rest. If you cannot name the owner in five minutes, it is already a leak waiting on a crawler.
  • Turn on alerting that fires on first-use geography, sudden object-store enumeration, and after-hours bulk reads for those identities. Wire those alerts to incident response, not a weekly digest. Pair them with egress controls so a “successful” API user still has to fight your network on the way out.
  • Force vendors who hold passenger, court, health, or HR stores to prove key rotation, logging retention you can pull, and a named 24/7 contact. Put that in the contract you can actually exercise, not the security questionnaire they screenshot once a year.
  • Pre-stage containment: disable-by-id runbooks, object-lock or legal-hold patterns you have tested, and a communications tree that does not wait for legal to discover the leak site on Twitter.

Ongoing security hardening looks less glamorous. Short-lived credentials instead of immortal admin keys. Separate identities for backup, replication, and human break-glass, so one stolen secret cannot do all three jobs. Regular access reviews that include automation users, because those are the ones nobody wants to touch. Hunt for secrets in tickets, CI variables, golden images, and that one shared mailbox the NOC still uses. Your firewall rules and your identity logs have to tell the same story, or you’ll spend the first six hours of IR arguing about which one is lying.

Practice the ten-hour version. Assume the copy job is already running. Who can revoke the principal without waiting for the identity team to land. Who can freeze the bucket. Who calls the vendor. Who is forbidden from saying the word “sealed” as if it were a control. If that rehearsal feels awkward, good. Awkward is cheaper than 550GB.

Padlock on a laptop representing cloud access control and vendor-hosted records
Valid cloud credentials make bulk export look like administration. Instrument the identity, not just the perimeter.

Cybersecurity that waits for the leak site is late

Leak sites are a pressure tool. Sometimes the archive is real. MAG’s reporting points at a very real pile of passenger-adjacent data. Thomson Reuters is telling courts and individuals to treat exposure as live. Your job is not to score the gang’s marketing. Your job is to know, from your own telemetry and your vendor’s, which identities could have done a bulk pull, whether they did, and what you rotated before lunch.

I want payment policy debates in the board packet. I want them in the appendix. The cover slide should be key sprawl, vendor admin paths, and how fast you can make a stolen secret stop working. That is the control that 8.8 million people actually needed. Everything after “we refused to pay” is damage reports.

You’ll still get ransomed again. Everyone in this business does, or will. The teams that look less foolish afterward are the ones who already treated admin keys like production, court platforms like production, and a ten-hour copy window like the clock they actually live on.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.