The UK Information Commissioner’s Office announced its intention to fine British Airways £183.39 million under GDPR over a 2018 cyber attack. The proposed penalty was the largest the ICO had ever announced.
What happened
- In 2018 users of the British Airways website were diverted to a fraudulent site where attackers harvested their details.
- Personal data of around 500,000 customers, including payment card details, was compromised.
- The ICO said poor security arrangements at the company had allowed the attack to succeed.
- In October 2020 the ICO issued a final fine of £20 million, taking into account representations and the impact of the pandemic.
Why it mattered
The announcement signalled that the ICO was prepared to use its new GDPR powers against major UK brands, even though the final penalty was much lower. It also raised the profile of web skimming attacks, in which criminals tamper with payment pages to steal card details as customers type them.
Lessons for organisations
Protect payment pages against script injection, monitor website code for unauthorised changes, and apply controls such as those in ISO/IEC 27001 and PCI DSS to customer-facing systems.
Sources: Pinsent Masons, Orrick
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.