Manchester Evening News

BA faces £500m data breach fine

-

BRITISH AIRWAYS is facing a multimilli­onpound fine as it grapples with the fallout of a massive data breach which the airline’s chief executive has described as a “malicious criminal attack”.

Thousands of BA customers have had to cancel their credit cards after the 15-day data hack compromise­d 380,000 payments.

Cyber criminals behind the attack obtained enough credit card details to use them, and the firm now faces a possible fine of around £500 million over the breach, with regulators now investigat­ing the incident.

BA’s data breach took place after the introducti­on of the new Data Protection Act, which includes the provisions of the new European General Data Protection Regulation, or GDPR.

Under the new regulation­s, the maximum penalty for a company hit with a data breach is a fine of either £17 million or 4% of global turnover, whichever is greater.

In the year ended December 31 2017, BA’s total revenue was £12.2 billion, meaning the company could face a fine of around £500 million if the Informatio­n Commission­er’s Office (ICO) takes action.

Multiple regulators have been contacted about the data hack, including the National Crime Agency, the National Cyber Security Centre and the ICO.

Alex Cruz, BA’s chairman and chief executive, said: “There was a very sophistica­ted, malicious criminal attack on our website.

“We became aware initially on that day, and we began to work on it. We discovered that something had happened, and immediatel­y we began to work.”

Shares in IAG, BA’s parent firm, were down more than 3% in morning trade as investors digested the news.

Mr Cruz apologised for the failure, adding that BA is “100% committed” to compensati­ng financiall­y affected customers.

“We’re extremely sorry. I know that it is causing concern to some of our customers, particular­ly those customers that made transactio­ns over BA.com and our app.”

He added: “We know that the informatio­n that has been stolen is name, address, email address, credit card informatio­n; that would be credit card number, expiration date and the code in the back of the credit card.

“No itinerary informatio­n, no frequent flier data, no passport data has been compromise­d.”

BA said it was investigat­ing the breach, which took place from 11pm on August 21 until 9.45pm on Wednesday, and is cooperatin­g with relevant regulators.

The incident comes after an IT meltdown caused huge disruption for BA passengers at the start of the May half-term holiday.

Some 75,000 passengers were left stranded after a glitch forced the airline to cancel nearly 726 flights over three days.

Following the latest breach, worried customers rushed to social media and helplines after the airline urged anyone who suspected they may have been affected to contact their bank or credit card provider.

 ??  ?? British Airways owner IAG saw shares fall 3%
British Airways owner IAG saw shares fall 3%

Newspapers in English

Newspapers from United Kingdom