British Airways Suf...
 

British Airways Suffers HUGE Data Breach, Could Face $500+ Million Fine

39 Posts
11 Users
0 Reactions
258 Views
Posts: 0
Diamond
Topic starter
(@james)
Member
Joined: 8 years ago
[#8251]
wpf-cross-image

Recently I wrote about how almost two million Air Canada customers were locked out of the Air Canada app following a security breach. Fortunately, only ~1% of those 1.7 million members (around 20,000) actually had their personal data compromised. Well now British Airways has suffered a much bigger security breach, and I was one of…

Continue reading: British Airways Suffers HUGE Data Breach, Could Face $500+ Million Fine

Share your questions, experiences, and thoughts below.


38 Replies
38 Replies
(@Debit)
Joined: 9 years ago

Posts: 476

Wow $500 million fine? Here in the USA if something like this were too happen the Congress would hold some useless hearings and the president would distract by blaming immigrants or making a big deal about NFL games. Remember only two kinds of Republicans: pure evil or completely stupid. But deserve a punch in the face.


Reply
(@DaninMCI)
Joined: 14 years ago

Posts: 399

Is it any surprise. We've all seen how Rock solid the BA website IT is so I assume this carries into other IT areas. Oh and....Insert bitter liberal off topic Trump hate comment here...


Reply
(@User Name)
Joined: 8 years ago

Posts: 1

Can we have a “like” feature for comments?


Reply
Gold
(@2paxfly)
Joined: 5 years ago

Member
Posts: 0

In my experience Amex is the best credit company regarding cybersecurity. Despite nearly all of their other services being downgraded or disappearing (am I the only person that remembers visiting Amex offices in each European city, because that's the easiest way your relatives could contact you?) - they have maintained 'having your back' in these sort of situations.

Unless Amex recommend it - I would not be changing my card - even though 'common sense' (that least reliable instict) says you should.

Oh, and have a fabulous 4 months of travel. Someone has to keep up Australian's reputation for outragous lengths of holidays!


Reply
(@geoshina)
Joined: 5 years ago

Member
Posts: 0

A question: aren’t you guys able to create a virtual credit card number associated with your original card in order to do online shopping?
You are able to create an one time purchase number, date and cvv code.

It does not solve all the data acquired, but at least you can forget about people using you credit card.


Reply
 jeff
(@jeff)
Joined: 12 years ago

Posts: 140

@George: Chase and Amex do not have this feature. One of the other companies (perhaps BOA) does. It is a great security feature that should be expanded.


Reply
(@MajoredinMiles)
Joined: 8 years ago

Posts: 2

4% of gross revenue would only be fined if BA had done nothing to comply with GDPR. If they had made reasonable efforts and completed a cyber risk assessment, I doubt their fine would be over a couple million, if anything at all. These things happen and it’s tough to prove negligence.


Reply
(@dakaix)
Joined: 5 years ago

Member
Posts: 0

I was also caught up in this, I called Amex UK on Thursday evening and requested a new card. They immediately re-issued this, and it arrived in the post on Saturday. Remarkably fast turnaround.


Reply
(@Brian)
Joined: 12 years ago

Posts: 37

If you have the card in Apple Pay they card there has a different number and can be used after the parent card has been marked compromised.

Not useful for every situation, but pretty much covers every day-to-day transaction here in Canada


Reply
 Joey
Diamond
(@joey-4)
Joined: 5 years ago

Member
Posts: 1214

Wow 4 months! That's awesome!!! Normally when I've had fraud activity on my cc (whether it be Chase, Amex, or Citi) they're quite fast. The majority of the time they tell me that I'll get the new card within 5-7 business days but I always ask if it's possible for them to overnight it and 100% of the time they provide it (at no extra charge). That's in the USA though... so am not sure if that's the same case for the BA Amex. Good luck!


Reply
(@vlcnc)
Joined: 10 years ago

Posts: 556

Wow, you guys were real slow reporting on this one...


Reply
 JB
(@JB)
Joined: 8 years ago

Posts: 5

@james

Totally agree it ‘can happen’ to any airline like we saw with AC.

What was bad was BA’s answer: putting it on the banks and basically telling you ‘may’ have been affected. It felt very amateurish. In comparison, Amex answer sounded much more thoughtful, reassuring and competent.


Reply
 Brad
(@brad)
Joined: 5 years ago

Member
Posts: 0

BA was also not following the PCI rules regarding the CVV as a merchant cannot store that data. That would leave them fully liable for any fraud, so as a customer, you would have nothing to worry about.


Reply
(@Hardy22)
Joined: 9 years ago

Posts: 18

@James: I think you don't need to worry missing your (eventual) new Amex card while not at home. Doesn't Amex provide you with a new card within 24 hours or so by delivery no matter where in the world you are?


Reply
(@airfarer)
Joined: 5 years ago

Posts: 0

I was also affected by this breach. Bought two tickets within that time period. They are being remarkably elusive with regards to compensation. I too canceled my card and had it reissued. Now need to change the number with the auto charges attached to the old card. I real pain. Nothing that 100,000 miles wouldn't cure though.


Reply
 Lee
(@Lee)
Joined: 8 years ago

Posts: 2

This came out the 2nd day into my holiday; to say I was livid would be an understatement. Unable to make contact with anyone about the issue where I am and woefully inadequate information in BA’s email lead to several ruined days worrying. My credit card provider emailed me 2 days afterwards off their own back to say they were issuing a new card... which is great, except it’s 4,000 miles away. Consequently I have not been able to book excursions, etc.

Well done BA. Ruined a holiday to paradise without even being on one of your delapidated uncomfortable aircraft!


Reply
(@emercycrite)
Joined: 12 years ago

Posts: 91

Mr Smithson!


Reply
 JDS
(@JDS)
Joined: 9 years ago

Posts: 180

Are you aware the letter on GDPR from May reveals your surname? No worries if you're cool with that, just mentioning it...


Reply
 JDS
(@JDS)
Joined: 9 years ago

Posts: 180

@emercycrite, you beat me to it!


Reply
(@Icarus)
Joined: 10 years ago

Posts: 2562

It’s made very difficult by the fact customers need to speak to frontline staff who can do almost nothing and get the blame

The CVV should not be stored

Debit knows nothing about travel, however always comments for reasons unknown to anyone


Reply
(@eskimo)
Joined: 9 years ago

Posts: 6164

The old @Debit is back.

And for US based people who needs some translation. Turnover = Revenue. Profit = Net Income.

@James - Your data that got stolen are minimal. I wouldn't worry too much especially with AMEX. They tend to be among the best with customers when things go south. I would just live life like normal and pay attention to charges, like what every person should be doing with any bills. I assume you hardly use the card for other purchases will make suspicious transaction stand out easier. I have been affected by numerous data breach yet the only time I lost faith in the system was Equifax. A year later, no accountability no changes. This is the most impacted breach in the history, those crappy 1 billion Yahoo account (people still use Yahoo???) didn't get as much sensitive information as this (147 out of 325 Americans lost sensitive data).


Reply
(@Chris)
Joined: 9 years ago

Posts: 33

Although PCI DSS does say that the CVV2 /CSC/etc should not be stored (anyone calling it a CVV is wrong), the rules can be read to state that it cannot be stored after authorisation, but can be prior.

Further, depending on the nature of the breach, storage of the value may have nothing to do with how the data was exfiltrated.


Reply
(@connie)
Joined: 5 years ago

Member
Posts: 0

I was one of those affected! Right before we leave on vacation this week!(oh yes, leaving our dog who is sick and trying to avoid two hurricanes-YIPPE!) I tweeted BA and they replied they are working on "compensation." What will that mean?


Reply
(@Andromeda)
Joined: 10 years ago

Posts: 50

"I must admit a chill went down my spine when I first heard the time frame of the breach, because I instantly knew I was within it."

Son, if a chill goes down your spine because of news of a cyber hack you are going to have to toughen up. There'll be worse to come as cyber crime increases, mark my words.

I was also "caught up" in the British Airways incident and I can't see the point in getting overly exercised about it. The workload I'd scheduled for Friday morning ( 7th September) was disrupted as it took almost an hour to get through to American Express to check the status of my account. When, eventually, I got a reply Amex were professional and reassuring. I'd not be liable should my card details be used fraudulently.

Take a back step and see what's going on in the world right now and this incident - as irritating and inconvenient as it is - pales into insignificance compared with major events.

Given the choice, I'd rather have been at home on the phone to Amex on Friday morning than have been in Hokkaido. Or Idlib. Or Chad.


Reply
(@Andromeda)
Joined: 10 years ago

Posts: 50

Connie - I expect compensation will mean being reimbursed for the figure you have lost. If, indeed, you have lost any funds due to fraud.


Reply
(@Andromeda)
Joined: 10 years ago

Posts: 50

Is someone deleting replies?


Reply
Diamond
(@james)
Joined: 8 years ago

Member
Posts: 0

@ Andromeda - the language you used gets caught in the spam filter and needs to be manually reviewed and approved.


Reply
(@tony-meola)
Joined: 5 years ago

Member
Posts: 0

I'm in it, too.


Reply
 Tom
(@Tom)
Joined: 12 years ago

Posts: 575

I'm with @Andromeda. People need to realize that consumers are not liable for fraudulent credit card charges. Never use debit for these purchases, so you don't have to deal with having your bank account drained and needing to get your money back.

@Lee, you should travel with more than one credit card or debit card to deal with situations like this. I usually have 3+ credit cards and 2 debit cards on a trip.


Reply
 Lee
(@Lee)
Joined: 8 years ago

Posts: 2

@Tom apparently so ... but the point is I shouldn’t have to. Trust us, they said ...


Reply
 Joe
(@Joe)
Joined: 10 years ago

Posts: 749

@george. For a while amex was experimenting with disposable credit card numbers. I loved it even though it was a bit of a pain to use. But they abruptly canceled it after almost a year. Guessing someone figured out a way to abuse it and generate their own disposable numbers.


Reply
(@majik)
Joined: 10 years ago

Posts: 108

The Air Canada breach was quietly brushed under the carpet even though it is much more serious than the BA breach. Though inconvenient, credit cards can be much more easily cancelled and replaced, not so much passports and Nexus cards.

While initially denying that there was any major danger with passport info being breached, AC are now backtracking and offering to cover the cost of a new passport for those affected.


Reply
 Bob
(@Bob)
Joined: 9 years ago

Posts: 6

Re. the £500 million fine... Won't BA just add a few pounds to "carrier imposed surcharges so we can pay for this? Or maybe they could load a few more M&S sandwiches to each flight and use that revenue.


Reply
 annx
(@annx)
Joined: 9 years ago

Posts: 10

Yes, I purchased a return biz BA ticket SFO-LHR on my AmEx Business Platinum right in the zone, my first purchase to start off my spend for the 100k bonus. Quite deflated after this news; sent a secure message asking AmEx what's needed, if anything, but sounds like they are on top of it.


Reply
Diamond
(@james)
Joined: 8 years ago

Member
Posts: 0

@ majik - there were 20 times the number of BA affected customers than AC customers remember....


Reply
Diamond
(@david-7)
Joined: 5 years ago

Member
Posts: 1023

@James
If you do go down the route of getting a new AMEX, you can always have it sent to your hotel so you don't have to wait 4 months before getting it.


Reply
(@majik)
Joined: 10 years ago

Posts: 108

@James. BA is a much bigger airline than Air Canada, that doesn't make it more serious, just that more were impacted.

With BA it's only credit card data which is easily backstopped by the credit card issuer's own fraud prevention methods. If you want a new credit card, that's a few clicks on website or a simple phone call away, not so with a passport or Nexus card. This then has a knock on effect to those visas and other immigration documents tied to that passport. That's just the inconvenience aspect. Now for the serious stuff.

A passport is what is called in security circles a root identity document, one on which others are based. Next in line is your social insurance and health insurance details and so on and so forth, you get the idea. The Air Canada breach was extremely serious even the Beeb chimed in:

*The City of London's Action Fraud team told the BBC that the "consequences of having your passport information accessed can be severe".**

But sure, some people had their easily replacable CC info hacked...


Reply
(@Rohan)
Joined: 8 years ago

Posts: 2

@James: just want to point out the Information Commissioner's Office is a domestic UK body, rather than European. It has the authority (and the obligation) to investigate GDPR breaches in the UK.


Reply