Don’t do SECURITY. Do business SECURELY.

British Airways reveals theft of customer payment card data

BA said attackers stole payment card details from its website and app, leading to a £20m ICO fine in 2020.

British Airways disclosed that customer payment card details had been stolen from its website and mobile app over about two weeks. The incident later led to a £20m fine from the Information Commissioner’s Office. Researchers linked the attack to the Magecart group of card-skimming criminals.

What happened

  • Attackers modified a script on BA’s website to divert card details entered by customers to a server they controlled.
  • BA initially said around 380,000 payment card transactions between 21 August and 5 September 2018 were affected.
  • The ICO said the personal data of around 429,000 customers and staff was affected.
  • The ICO had proposed a fine of £183m in 2019 but issued a final penalty of £20m in October 2020.

Why it mattered

It was one of the first major UK breaches investigated under GDPR, and it showed how web supply chain attacks on payment pages could hit large brands.

Lessons for organisations

Monitor website scripts for unauthorised changes, apply integrity controls to third-party code, and limit access to systems handling payment data. PCI DSS and ISO/IEC 27001 support these controls.

Source: CNBC

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights