British Airways disclosed that customer payment card details had been stolen from its website and mobile app over about two weeks. The incident later led to a £20m fine from the Information Commissioner’s Office. Researchers linked the attack to the Magecart group of card-skimming criminals.
What happened
- Attackers modified a script on BA’s website to divert card details entered by customers to a server they controlled.
- BA initially said around 380,000 payment card transactions between 21 August and 5 September 2018 were affected.
- The ICO said the personal data of around 429,000 customers and staff was affected.
- The ICO had proposed a fine of £183m in 2019 but issued a final penalty of £20m in October 2020.
Why it mattered
It was one of the first major UK breaches investigated under GDPR, and it showed how web supply chain attacks on payment pages could hit large brands.
Lessons for organisations
Monitor website scripts for unauthorised changes, apply integrity controls to third-party code, and limit access to systems handling payment data. PCI DSS and ISO/IEC 27001 support these controls.
Source: CNBC
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.