Skip to main content
Breach Signal

Breach report

Travel & Hospitality

British Airways

British Airways fined £20 million for data breach by ICO

Hackers slipped card-skimming code into British Airways' website and app in 2018, capturing payment details from about 429,000 customers and staff and triggering what was then the U.K. privacy regulator's largest-ever fine.

Reported by CNBC

Records exposed

430K

About 429,612 customers and staff

Scale vs. largest on file

When
2018
How they got in
Magecart-style card skimming script injected into website and app
Sector
Travel & Hospitality

In September 2018, British Airways disclosed that customers who booked through its website and mobile app over roughly two weeks, from late August to early September, had their personal and payment details stolen. The airline initially put the number of affected transactions at around 380,000, and weeks later said an additional group of customers who made reward bookings earlier in the year may also have been affected. The U.K. Information Commissioner's Office ultimately found that 429,612 customers and staff were impacted.

Security researchers linked the attack to Magecart, a loose collection of groups that specialize in injecting malicious JavaScript into e-commerce pages. The attackers had modified a script on BA's payment pages so that card details typed by customers were silently copied to a server under the criminals' control, using a domain crafted to resemble a legitimate BA address. The ICO's investigation found that the intruders first gained access using login credentials for a third-party supplier's account that lacked multifactor authentication, and that BA took more than two months to detect the intrusion.

The stolen information included names, addresses and full payment card details, including card numbers, expiry dates and CVV security codes for about 244,000 people. Others had partial card data taken, and usernames and passwords of up to 612 Executive Club loyalty accounts may have been accessed. Because CVV codes were captured in real time, the data was immediately usable for fraud.

In July 2019 the ICO announced its intention to fine BA £183 million, the first major penalty proposed under the EU's General Data Protection Regulation. After representations from the airline and taking into account the financial blow of the Covid-19 pandemic on aviation, the regulator reduced the final penalty in October 2020 to £20 million, still the largest it had issued at that time. BA also faced a group legal action on behalf of affected customers, which it settled in 2021 on undisclosed terms without admitting liability.

The case became a reference point for how GDPR would be enforced and for the dangers of client-side attacks, in which criminals tamper with code running in the customer's browser rather than breaching back-end databases. It pushed online merchants to monitor third-party scripts on payment pages and to require multifactor authentication for supplier and remote access accounts. For consumers, it showed that even a trusted brand's checkout page can be compromised without any visible warning.

More from the wire

More in Travel & Hospitality.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.