{"id":4596,"date":"2019-07-08T20:07:31","date_gmt":"2019-07-08T14:37:31","guid":{"rendered":"https:\/\/qadit.com\/blog\/?p=4596"},"modified":"2019-07-08T20:07:31","modified_gmt":"2019-07-08T14:37:31","slug":"british-airways-fined-183-million-under-gdpr-over-2018-data-breach","status":"publish","type":"post","link":"https:\/\/qadit.com\/blog\/british-airways-fined-183-million-under-gdpr-over-2018-data-breach\/","title":{"rendered":"British Airways Fined \u00a3183 Million Under GDPR Over 2018 Data Breach"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/1.bp.blogspot.com\/-wN253fYw19w\/XSL5FMQFLeI\/AAAAAAAA0Wc\/rAMiUyLoTssNqhi5SWgHcru9xCsXh7AAQCLcBGAs\/s728-e100\/british-airways-gdpr-fine-data-breach.png\" title=\"British Airways Fined &#163;183 Million Under GDPR Over 2018 Data Breach\" \/><\/p>\n<div>\n<div id=\"articlebody\">\n<p> Britain&#8217;s Information Commissioner&#8217;s Office (ICO) today hit British Airways with a record fine of &#163;183 million for failing to protect the personal information of around half a million of its customers during <\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2018\/09\/british-airways-data-breach.html\" target=\"_blank\">last year&#8217;s security breach<\/a><\/p>\n<p>. <\/p>\n<p> British Airways, who describes itself as &#8220;The World&#8217;s Favorite Airline,&#8221; disclosed a breach last year that exposed personal details and credit-card numbers of up to 380,000 customers and lasted for more than two weeks. <\/p>\n<p> At the time, the company confirmed that customers who booked flights on its official website (ba.com) and British Airways mobile app between August 21 and September 5 had had their details stolen by attackers. <\/p>\n<p> The cyberattack was later attributed to the infamous <\/p>\n<p><b>Magecart<\/b><\/p>\n<p> threat actor, one of the most notorious hacking groups specialized in stealing credit card details from poorly-secured websites, especially online eCommerce platforms. <\/p>\n<p> Magecart hackers have been known for using digital credit card skimmer wherein they secretly insert a few lines of malicious code into the checkout page of a compromised website that captures payment details of customers and then sends it to a remote server. <\/p>\n<p><ins \/> <\/p>\n<p> Besides British Airways, Magecart groups have also been responsible for card breaches on sites belonging to high-profile companies like <\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2018\/06\/ticketmaster-data-breach.html\" target=\"_blank\">TicketMaster<\/a><\/p>\n<p>, <\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2018\/09\/newegg-credit-card-hack.html\" target=\"_blank\">Newegg<\/a><\/p>\n<p>, as well as sites belonging to other <\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2019\/01\/magecart-hacking-credit-cards.html\" target=\"_blank\">small online merchants<\/a><\/p>\n<p>. <\/p>\n<p> In a statement <\/p>\n<p><a href=\"https:\/\/ico.org.uk\/about-the-ico\/news-and-events\/news-and-blogs\/2019\/07\/ico-announces-intention-to-fine-british-airways\/\" target=\"_blank\">released today<\/a><\/p>\n<p>, ICO said its extensive investigation found that a variety of information related to British Airways&#8217; customers was compromised by &#8220;poor security arrangements&#8221; at the company, including their names and addresses, log-ins, payment card data, and travel booking details. <\/p>\n<blockquote><p> &#8220;People&#8217;s personal data is just that &#8211; personal. When an organization fails to protect it from loss, damage or theft, it is more than an inconvenience,&#8221; Information Commissioner Elizabeth Denham said.<\/p><\/blockquote>\n<blockquote><p> &#8220;That&#8217;s why the law is clear &#8211; when you are entrusted with personal data, you must look after it. Those that don&#8217;t will face scrutiny from my office to check they have taken appropriate steps to protect fundamental privacy rights.&#8221;<\/p><\/blockquote>\n<p> However, ICO also said that British Airways has cooperated with its investigation and has made improvements to the security arrangements since the last year data breach came to light. <\/p>\n<p> Since the data breach happened after the EU&#8217;s General Data Protection Regulation (GDPR) took effect on May 2018, the fine of &#163;183.39 million has been imposed on British Airways, which is the equivalent of 1.5% of the company&#8217;s worldwide turnover for its 2017 financial year but is still less than the possible maximum of 4%. <\/p>\n<p><ins \/> <\/p>\n<p> In response to the ICO announcement, British Airways, owned by IAG, said the company was &#8220;surprised and disappointed&#8221; by the ICO penalty. <\/p>\n<blockquote><p> &#8220;British Airways responded quickly to a criminal act to steal customers&#8217; data,&#8221; said British Airways chairman and chief executive Alex Cruz.<\/p><\/blockquote>\n<blockquote><p> &#8220;We have found no evidence of fraud\/fraudulent activity on accounts linked to the theft. We apologize to our customers for any inconvenience this event caused.&#8221;<\/p><\/blockquote>\n<p> The company has 28 days to appeal the penalty. <\/p>\n<p> Until now, the most significant penalty by the UK&#8217;s data protection watchdog was &#163;500,000, which was <\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2018\/10\/facebook-cambridge-analytica.html\" target=\"_blank\">imposed on Facebook<\/a><\/p>\n<p> last year for allowing political consultancy firm Cambridge Analytica to gather and misuse data of 87 million users improperly. <\/p>\n<p> The same penalty of &#163;500,000 was also imposed on <\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2018\/09\/equifax-credit-reporting-breach.html\" target=\"_blank\">credit reporting agency Equifax<\/a><\/p>\n<p> last year for its 2017&#8217;s massive data breach that exposed the personal and financial information of hundreds of millions of its customers. <\/p>\n<p> Since both the incidents in Facebook and Equifax occurred before GDPR took effect, &#163;500,000 was the maximum penalty ICO can impose under the UK&#8217;s old Data Protection Act. <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<p><b>Read the Full Article here: <a href=\"https:\/\/thehackernews.com\/\">&gt;The Hacker News [ THN ]<\/a><\/b><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Britain&#8217;s Information Commissioner&#8217;s Office (ICO) today hit British Airways with a record fine of &#163;183 million for failing to protect the personal information of around half a million of its customers during last year&#8217;s security breach . British Airways, who describes itself as &#8220;The World&#8217;s Favorite Airline,&#8221; disclosed a breach last year that exposed personal &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/qadit.com\/blog\/british-airways-fined-183-million-under-gdpr-over-2018-data-breach\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;British Airways Fined \u00a3183 Million Under GDPR Over 2018 Data Breach&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[12],"tags":[293],"class_list":["post-4596","post","type-post","status-publish","format-standard","hentry","category-itsec","tag-wonder-information"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9AH7Q-1c8","_links":{"self":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/4596","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/comments?post=4596"}],"version-history":[{"count":1,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/4596\/revisions"}],"predecessor-version":[{"id":4597,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/4596\/revisions\/4597"}],"wp:attachment":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/media?parent=4596"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/categories?post=4596"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/tags?post=4596"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}