Breach report
Travel & HospitalityBritish Airways
British Airways fined £20 million for data breach by ICO
Hackers slipped card-skimming code into British Airways' website and app in 2018, capturing payment details from about 429,000 customers and staff and triggering what was then the U.K. privacy regulator's largest-ever fine.
Reported by CNBC
Records exposed
430K
About 429,612 customers and staff
Scale vs. largest on file
- When
- 2018
- How they got in
- Magecart-style card skimming script injected into website and app
- Sector
- Travel & Hospitality
In September 2018, British Airways disclosed that customers who booked through its website and mobile app over roughly two weeks, from late August to early September, had their personal and payment details stolen. The airline initially put the number of affected transactions at around 380,000, and weeks later said an additional group of customers who made reward bookings earlier in the year may also have been affected. The U.K. Information Commissioner's Office ultimately found that 429,612 customers and staff were impacted.
Security researchers linked the attack to Magecart, a loose collection of groups that specialize in injecting malicious JavaScript into e-commerce pages. The attackers had modified a script on BA's payment pages so that card details typed by customers were silently copied to a server under the criminals' control, using a domain crafted to resemble a legitimate BA address. The ICO's investigation found that the intruders first gained access using login credentials for a third-party supplier's account that lacked multifactor authentication, and that BA took more than two months to detect the intrusion.
The stolen information included names, addresses and full payment card details, including card numbers, expiry dates and CVV security codes for about 244,000 people. Others had partial card data taken, and usernames and passwords of up to 612 Executive Club loyalty accounts may have been accessed. Because CVV codes were captured in real time, the data was immediately usable for fraud.
In July 2019 the ICO announced its intention to fine BA £183 million, the first major penalty proposed under the EU's General Data Protection Regulation. After representations from the airline and taking into account the financial blow of the Covid-19 pandemic on aviation, the regulator reduced the final penalty in October 2020 to £20 million, still the largest it had issued at that time. BA also faced a group legal action on behalf of affected customers, which it settled in 2021 on undisclosed terms without admitting liability.
The case became a reference point for how GDPR would be enforced and for the dangers of client-side attacks, in which criminals tamper with code running in the customer's browser rather than breaching back-end databases. It pushed online merchants to monitor third-party scripts on payment pages and to require multifactor authentication for supplier and remote access accounts. For consumers, it showed that even a trusted brand's checkout page can be compromised without any visible warning.