Case study

Case Study - British Airways

4 slides · 2 min read · Domain 8

Case Study: British Airways

On October 16, 2020, Elizabeth Denham, a commissioner for the Information Commissioner's Office (ICO) concluded the following of British Airways (BA): "People entrusted their personal details to BA and BA failed to take adequate measures to keep those details secure."

She continued by stating, "Their failure to act was unacceptable and affected hundreds of thousands of people, which may have caused some anxiety and distress as a result. That's why we have issued BA with a €20 million fine —our biggest to date."

"When organizations make poor decisions around people's personal data, that can have a real impact on people's lives. The law now gives us the tools to encourage businesses to make better decisions about data, including investing in up-to-date security," Denham said.

While you may think of £20 million as a heavy fine, it's not quite as large as you might think. Before the COVID-19 pandemic, the fine was originally £184 million, or 1.5% of BA's revenue for 2018 (the year of the attack and subsequent breach).

A failure in security procedures and software resulted in a data breach that affected 429,612 customers and staff. The information exposed included names, addresses, payment card details, and CVV numbers.

Further compounding the gravity of the situation, BA never detected the attack— they learned about it from a third party.

The full details of the attack have not been made public (which is not uncommon), but two main theories prevail: either users were re-directed to a spoofed BA website, or the attackers managed to load scripts onto BA's legitimate website, capturing the information at the point-of-entry. By placing an attack here, any time users made bookings or logged in to manage their accounts, the attackers were able to skim the information they wanted and have those details sent directly to themselves. Because the CVV numbers were collected "live," according to Robert Pritchard, a former cybersecurity researcher at Government Communications Head Quarters (GCHQ), this latter theory seems most likely.

Test this domain