Back to the archive

The encyclopedia · Legal & Compliance · Operational decision · 2018–2020

British Airways let 22 lines of stolen JavaScript skim card details for 15 weeks

Attackers diverted BA's ba.com payment page to a look-alike, harvesting 429,612 customers' data. The ICO fined BA £20m, its largest GDPR penalty to date.

British Airways · 2018-06-22

What happened

From 22 June 2018, attackers who had entered BA's systems through a compromised third-party account modified the British Airways website and app so that customers' payment and personal details were copied to a fraudulent server. The malicious code — about 22 lines of JavaScript, later attributed to Magecart-style web-skimming groups — diverted traffic to a look-alike domain, 'baways.com', and ran undetected for over two months.

On 5 September 2018 an external party told BA its data was being exfiltrated. By then the attacker had potentially accessed the personal data of approximately 429,612 customers and staff, including names, addresses, login details and payment card numbers — and the combined card and CVV security codes of about 77,000 customers.

In July 2019 the ICO issued a notice of intent to fine BA £183.39 million, about 1.5% of its 2017 global turnover, which would have been a record. After BA's representations the regulator reset the baseline to £30 million: a £6m reduction for BA's swift containment, notification and cooperation, and a further £4m reduction for the impact of Covid-19 on the airline's finances. The final penalty, issued on 16 October 2020, was £20 million — still the ICO's largest GDPR fine at the time.

A group action on behalf of affected customers, described as the largest personal-data claim in UK history, was settled out of court in 2021. The ICO's penalty notice records that BA breached GDPR Article 5(1)(f) and Article 32 — failing to ensure appropriate security of personal data.

Why it happened

  • The relevant BA systems were not protected by multi-factor authentication, so stolen credentials from a third-party supplier let the attacker straight in.
  • BA did not run rigorous security testing of the kind that simulates a cyber-attack, nor deploy file-integrity monitoring that would have flagged the injected script.
  • It did not adequately identify or mitigate the risks of remote access and of loading third-party JavaScript on its payment pages.
  • A testing-feature error had left some card details and CVV codes retained in plain text, so the skimmer could capture more than it should have been able to.
What it cost£20m ICO fine; 429,612 records exposedcostly

The lesson

A compromised third-party script is a breach that only one line of JS had to be right. Two dozen lines slipped through; fifteen weeks went by. The question is why the review let them through.

Aftermath

BA notified affected customers, offered credit monitoring and cooperated with the ICO, which factored into the reduced fine. The group-action claim settled out of court in 2021; the settlement figure was not disclosed. The case, alongside the Marriott penalty, set the benchmark for how the UK regulator sizes GDPR fines for poor data security.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →