BA hit by ‘sophisticated, malicious’ security hack

Sunday, 07 Sep, 2018 0

British Airways has launched an urgent investigation after it was hit by a major security breach.

Personal and financial data of nearly 400,000 customers was stolen from its website and mobile app, although BA stressed the data did not include travel or passport details.

The breach happened between August 21 and September 5 inclusive and targeted customers making bookings or changes to their bookings.

BA assured customers the breach has now been resolved and its website is working normally.

It has also notified the police and relevant authorities.

Chairman and chief executive Alex Cruz said: "We are deeply sorry for the disruption that this criminal activity has caused. We take the protection of our customers’ data very seriously."

Customers who believe they have been affected should contact their bank or credit card provider and follow their recommended advice.

BA said it is contacting affected customers directly to advise them of what has happened and says they will be fully reimbursed for a credit checking service.

It is also advising passengers to reset their passwords for its website and to choose a unique password not used on other online accounts.

Speaking to BBC Breakfast, Cruz said it was a ‘sophisticated, malicious criminal attack’.

He said it had been alerted to the attack by a ‘partner’.

The airline has taken out adverts apologising for the breach in today’s newspapers.

But some customers have complained that they have not been contacted by the airline and have only found out about the breach through the media.

Paul Farrington, head of EMEA at app security company CA Veracode, said it was shocking that it took 16 days to detect the breach.

He said IT issues are not only affecting BA but the wider airline industry.

"As airlines become ever more dependent on software, this creates a greater surface for hackers to attack and so it is no surprise that breaches of this scale are becoming commonplace," he said.

Shares in BA parent IAG were down almost 3% this morning.

Fiona Cincotta, senior market analyst at City Index, said the company was grappling with the aftermath.

"BA said that the attack was a sophisticated breach of its security system but this is the last in a series of IT problems the company has had this year including IT issues which caused flights in and out of Heathrow airport to be cancelled only six weeks ago," she said.
 



 

profileimage

Bev

Editor in chief Bev Fearis has been a travel journalist for 25 years. She started her career at Travel Weekly, where she became deputy news editor, before joining Business Traveller as deputy editor and launching the magazine’s website. She has also written travel features, news and expert comment for the Guardian, Observer, Times, Telegraph, Boundless and other consumer titles and was named one of the top 50 UK travel journalists by the Press Gazette.



Most Read

Vegas’s Billion-Dollar Secrets – What They Don’t Want Tourists to Know

Visit Florida’s New CEO Bryan Griffin Shares His Vision for State Tourism with Graham

Chicago’s Tourism Renaissance: Graham Interviews Kristin Reynolds of Choose Chicago

Graham Talks with Cassandra McCauley of MMGY NextFactor About the Latest Industry Research

Destination International’s Andreas Weissenborn: Research, Advocacy, and Destination Impact

Graham and Don Welsh Discuss the Success of Destinations International’s Annual Conference

Graham and CEO Andre Kiwitz on Ventura Travel’s UK Move and Recruitment for the Role

Brett Laiken and Graham Discuss Florida’s Tourism Momentum and Global Appeal

Graham and Elliot Ferguson on Positioning DC as a Cultural and Inclusive Global Destination

Graham Talks to Fraser Last About His England-to-Ireland Trek for Mental Health Awareness

Kathy Nelson Tells Graham About the Honour of Hosting the World Cup and Kansas City’s Future

Graham McKenzie on Sir Richie Richardson’s Dual Passion for Golf and His Homeland, Antigua
TRAINING & COMPETITION
Skip to toolbar
Clearing CSS/JS assets' cache... Please wait until this notice disappears...
Updating... Please wait...