Cyber-security firm claims to have discovered cause of BA’s data breach

Thursday, 11 Sep, 2018 0

British Airways has refused to comment on claims by a cyber-security firm that it has found the malicious script that caused the recent data breach which affected 380,000 transactions.

RiskIQ claims the script was injected into both BA’s website and its app, allowing hackers to steal customer’s financial information.

One of its researchers has analysed code from BA’s website and app from late August when the airline was hacked and claims to have discovered a ‘skimming’ script, which it said was similar to one that targeted Ticketmaster’s website recently.

It said the code found on BA’s website was ‘very similar’, but was modified to suit the way the airline’s site was designed.

However, BA said: "As this is a criminal investigation, we are unable to comment on speculation."

In a report on his findings, which has been seen by the BBC, the RiskIQ researcher said: "This particular skimmer is very much attuned to how British Airway’s payment page is set up, which tells us that the attackers carefully considered how to target this site instead of blindly injecting the regular Magecart skimmer.

"The infrastructure used in this attack was set up with British Airways in mind and purposely targeted scripts that would blend in with normal payment processing to avoid detection."

RiskIQ said the malicious script grabbed data from BA’s online payment form, then sent it to the hackers’ server when the customer hit the ‘submit’ button.

The same script was found on the BA app on a page describing government taxes and carrier charges, said RiskIQ.

BA is facing compensation claims from some of the 380,000 customers whose information was stolen.



 

profileimage

Linsey McNeill

Editor Linsey McNeill has been writing about travel for more than three decades. Bylines include The Times, Telegraph, Observer, Guardian and Which? plus the South China Morning Post. She also shares insider tips on thetraveljournalist.co.uk



Most Read

Vegas’s Billion-Dollar Secrets – What They Don’t Want Tourists to Know

Visit Florida’s New CEO Bryan Griffin Shares His Vision for State Tourism with Graham

Chicago’s Tourism Renaissance: Graham Interviews Kristin Reynolds of Choose Chicago

Graham Talks with Cassandra McCauley of MMGY NextFactor About the Latest Industry Research

Destination International’s Andreas Weissenborn: Research, Advocacy, and Destination Impact

Graham and Don Welsh Discuss the Success of Destinations International’s Annual Conference

Graham and CEO Andre Kiwitz on Ventura Travel’s UK Move and Recruitment for the Role

Brett Laiken and Graham Discuss Florida’s Tourism Momentum and Global Appeal

Graham and Elliot Ferguson on Positioning DC as a Cultural and Inclusive Global Destination

Graham Talks to Fraser Last About His England-to-Ireland Trek for Mental Health Awareness

Kathy Nelson Tells Graham About the Honour of Hosting the World Cup and Kansas City’s Future

Graham McKenzie on Sir Richie Richardson’s Dual Passion for Golf and His Homeland, Antigua
TRAINING & COMPETITION
Skip to toolbar
Clearing CSS/JS assets' cache... Please wait until this notice disappears...
Updating... Please wait...