Tuesday, March 4, 2025
HomeData BreachBritish Airways Hacked - More than 380,000 Payment Cards Compromised

British Airways Hacked – More than 380,000 Payment Cards Compromised

Published on

SIEM as a Service

Follow Us on Google News

British Airways Hacked, customers who made the booking through the website or mobile app from August 21, 2018, to September 5, 2018, are affected.

The attackers stole personal and financial details of 380,000 customers who made the booking through the website ba.com and mobile app.

https://twitter.com/British_Airways/status/1037755174700417025

British Airways confirmed that travel details, passport details, and stored payment card details are not affected.

British Airways spokesperson said “a third-party noticed some unusual activity and informed us about it. We immediately acted to close down the issue, and started an investigation as a matter of urgency.”

BA said that breach has been resolved now and the website is working normally now and they reported to the relevant authorities.

Also, the company started to email customers who could potentially be affected by this issue and BA requested the reset the ba.com account passwords.

“The incident has been resolved and ba.com is working normally so future bookings will not be affected, all customers booked on our flights will be able to check in as normal.” reads the company statement.

Last month a similar incident happened with Air Canada, as the attackers gained access to the mobile App and accessed more than 20,000 user accounts without proper authorization.

Also Read

Hackers Selling Airport Security System Credentials on Dark Web for $10

Australian Airport Hacked: Significant Amount of Security Data Stolen by Vietnamese Hacker

Boeing 757 Airplanes are Vulnerable to Remote Hacking

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Docusnap for Windows Flaw Exposes Sensitive Data to Attackers

A recently disclosed vulnerability in Docusnap's Windows client software (CVE-2025-26849) enables attackers to decrypt...

CISA Warns of Active Exploitation of Microsoft Windows Win32k Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2018-8639, a decade-old Microsoft Windows...

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under...

BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely

A critical vulnerability in BigAntSoft's enterprise chat server software has exposed ~50 internet-facing systems...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

260 Domains Hosting 5,000 Malicious PDFs to Steal Credit Card Data

Netskope Threat Labs uncovered a sprawling phishing operation involving 260 domains hosting approximately 5,000...

Authorities Arrested Hacker Behind 90 Major Data Breaches Worldwide

Cybersecurity firm Group-IB, alongside the Royal Thai Police and Singapore Police Force, announced the...

Orange Communication Breached – Hackers Allegedly Claim 380,000 Email Records Exposed

Telecommunications provider Orange Communication faces a potential data breach after a threat actor using the pseudonym “Rey”...