BA apologizes after 380,000 customers hit in cyberattack

Around 380,000 card payments to British Airways have been compromised, with hackers obtaining names, credit card numbers, expiry dates and security codes. (AFP)
Updated 07 September 2018
Follow

BA apologizes after 380,000 customers hit in cyberattack

  • The airline discovered that bookings made between Aug. 21 and Sept. 5 have been infiltrated in a very sophisticated criminal attack
  • The attack comes 15 months after the carrier suffered a massive computer system failure at London’s Heathrow airport

LONDON: British Airways apologized on Friday after the credit card details of hundreds of thousands of its customers were stolen over a two-week period in the most serious attack on its website and app.
The airline discovered on Wednesday that bookings made between Aug. 21 and Sept. 5 had been infiltrated in a “very sophisticated, malicious criminal” attack, BA Chairman and Chief Executive Alex Cruz said. It immediately contacted customers when the extent of the breach became clear.
Around 380,000 card payments were compromised, the airline said, with hackers obtaining names, street and email addresses, credit card numbers, expiry dates and security codes — sufficient information to steal from accounts.
The attack came 15 months after the carrier suffered a massive computer system failure at London’s Heathrow airport, which stranded 75,000 customers over a holiday weekend.
Shares in BA’s parent, International Airlines Group , were down 2 percent in afternoon trading on Friday.
Cruz said the carrier was “deeply sorry” for the disruption caused by the attack which was unprecedented in the more than 20 years that BA had operated online.
He said the attackers had not broken the airline’s encryption but did not explain exactly how they had obtained the customer information.
“There were other methods, very sophisticated efforts, by criminals in obtaining the data,” he told BBC radio.
IT security company Avast said that based on the limited information available the attackers had probably targeted a gateway between the airline and a payment processor because no travel details had been stolen.
“Quite often, when it’s just a hack of a database somewhere it is hard to identify when something has been compromised,” Avast’s consumer security expert Pete Turner said.
“This feels much more like a transaction-type attack, where data is moving about within the system.”
Britain’s government said authorities including the National Cyber Security Center and the National Crime Agency, part of the country’s police, were piecing together what happened.
“Specialist officers from the NCA’s National Cyber Crime Unit are managing the ongoing investigation and are on site working with BA to gain a better understanding of the incident,” the NCA said.
The country’s Information Commissioner’s Office said it had been alerted by BA and it was making enquiries. Under new GDPR data regulations companies must inform regulators of a cyberattack within 72 hours.
BA advised customers to contact their bank or credit card provider and follow their recommended advice. It also took out ads in national newspapers on Friday.
Cruz said anyone who lost out financially would be compensated by the airline.
Data security expert Trevor Reschke said that like any website which sees large volumes of card transactions, BA was a ripe target for hackers.
“It is now a race between British Airways and the criminal underground,” said Reschke, head of threat intelligence at Trusted Knight.
“One will be figuring out which cards have been compromised and alerting victims, whilst the other will be trying to abuse them while they are still fresh.”
NatWest, one of Britain’s biggest card issuers, said it was receiving higher-than-usual call volumes because of the breach.
It said in a recorded message that its security systems would likely stop any fraud as a result of the hack but anyone affected should look out for unusual activity on their accounts.
American Express said clients did not need to take any action and the company would alert anyone with unusual activity on their cards.
IAG said the data breach had been resolved and the website was working normally, and that no travel or passport details were stolen.
After the computer system failure in May 2017, BA said it would take steps to ensure such an incident never happened again, but in July it was forced to cancel and delay flights out of the same airport due to problems with a supplier’s IT systems.


SIDF concludes participation in Momentum 2025

Updated 11 December 2025
Follow

SIDF concludes participation in Momentum 2025

RIYADH: The Saudi Industrial Development Fund concluded its participation in the Development Finance Conference Momentum 2025 organized by the National Development Fund under the patronage of Crown Prince Mohammed bin Salman, prime minister and chairman of the NDF board.

The event was held from Dec. 9 to 11 at the King Abdulaziz International Conference Center in Riyadh.

The conference provided a platform to explore the future of development finance and its role in supporting sustainable growth. It brought together leading thinkers, investors, and decision-makers from around the world to discuss key challenges and opportunities, and to exchange experiences that enhance financing tools and maximize their developmental impact.

SIDF participation underscored its active role in supporting economic development through its financing advisory and knowledge-based programs as well as its diverse initiatives designed to meet the needs and aspirations of manufacturers and investors, aligning with the Kingdom's objectives and Vision 2030 targets.

In a panel discussion on the sidelines of the conference, Prince Sultan bin Khalid bin Faisal, CEO of SIDF, highlighted that the fund has, for more than 50 years, continued to develop its financing and advisory tools to empower national industries and enhance their global competitiveness.

He noted that SIDF has supported more than 4200 projects with total disbursements exceeding SR150 billion ($40 billion), attracting investments of nearly SR800 billion.

Prince Sultan added that the fund is currently focused on creating new financing channels in collaboration with government and private entities to provide sustainable funding for the private sector through mechanisms that attract capital and investors.

He said: “We recently launched the world’s largest supply chain financing program in collaboration with Saudi Aramco and the Saudi Electricity Co., benefiting thousands of suppliers and factories.”

SIDF participation culminated in signing a cooperation agreement with the Saudi Arabia Railways to identify opportunities for industrial sector support and to assist investors in localizing goods and services to increase domestic content.

The Momentum 2025 conference reflects the Kingdom's leading role across various development sectors, highlighting the contributions of its development ecosystem in shaping a sustainable developmental future that delivers economic and social impact in line with Vision 2030 objectives.

The conference serves as a platform for collaboration that advances the implementation of development finance solutions, bringing together leaders from government entities, development finance institutions, investors and innovators from within the Kingdom and abroad.

It aims to strengthen partnerships that align capabilities across the system and translate developmental priorities into actionable initiatives, fostering inclusive and sustainable growth.