Don’t do SECURITY. Do business SECURELY.

ICO announces intention to fine British Airways £183 million

The ICO says it intends to fine British Airways £183.39 million under GDPR after a 2018 attack exposed data on around 500,000 customers.

The UK Information Commissioner’s Office announced its intention to fine British Airways £183.39 million under GDPR over a 2018 cyber attack. The proposed penalty was the largest the ICO had ever announced.

What happened

  • In 2018 users of the British Airways website were diverted to a fraudulent site where attackers harvested their details.
  • Personal data of around 500,000 customers, including payment card details, was compromised.
  • The ICO said poor security arrangements at the company had allowed the attack to succeed.
  • In October 2020 the ICO issued a final fine of £20 million, taking into account representations and the impact of the pandemic.

Why it mattered

The announcement signalled that the ICO was prepared to use its new GDPR powers against major UK brands, even though the final penalty was much lower. It also raised the profile of web skimming attacks, in which criminals tamper with payment pages to steal card details as customers type them.

Lessons for organisations

Protect payment pages against script injection, monitor website code for unauthorised changes, and apply controls such as those in ISO/IEC 27001 and PCI DSS to customer-facing systems.

Sources: Pinsent Masons, Orrick

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights