• Home
  • Mail
  • News
  • Finance
  • Sports
  • Entertainment
  • Search
  • Mobile
  • More
Yahoo
    • Skip to Navigation
    • Skip to Main Content
    • Skip to Related Content
    • Mail
    Advertisement

    British Airways fined £20m over data breach

    BBC•October 20, 2020
    BA planes
    BA planes

    British Airways has been fined £20m ($26m) by the Information Commissioner's Office (ICO) for a data breach which affected more than 400,000 customers.

    The breach took place in 2018 and affected both personal and credit card data.

    The fine is considerably smaller than the £183m that the ICO originally said it intended to issue back in 2019.

    It said "the economic impact of Covid-19" had been taken into account.

    However, it is still the largest penalty issued by the ICO to date.

    The incident took place when BA's systems were compromised by its attackers, and then modified to harvest customers' details as they were input.

    It was two months before BA was made aware of it by a security researcher, and then notified the ICO.

    • How did hackers get into British Airways?

    • BA boss apologises for data breach

    The data stolen included log in, payment card and travel booking details as well name and address information.

    A subsequent investigation concluded that sufficient security measures, such as multi-factor authentication, were not in place at the time.

    The ICO noted that some of these measures were available on the Microsoft operating system that BA was using at the time.

    "When organisations take poor decisions around people's personal data, that can have a real impact on people's lives. The law now gives us the tools to encourage businesses to make better decisions about data, including investing in up-to-date security," said Information Commissioner Elizabeth Denham.

    British Airways said it had alerted customers as soon as it had found out about the attack on its systems.

    "We are pleased the ICO recognises that we have made considerable improvements to the security of our systems since the attack and that we fully co-operated with its investigation," said a spokesman.

    Data protection officer Carl Gottlieb said that in the current climate, £20m was a "massive" fine.

    "It shows the ICO means business and is not letting struggling companies off the hook for their data protection failures," he said.

    Analysis box by Joe Tidy, Cyber reporter
    Analysis box by Joe Tidy, Cyber reporter

    It's taken more than two years for BA to face the music over this extremely serious incident.

    The company breached data protection law and failed to protect themselves from preventable cyber attack. It then failed to detect the hack until the damage was done to hundreds of thousands of customers.

    The lag between incident and fine has raised eyebrows in privacy circles but I understand the Information Commissioner's Office has been working methodically to get it right. This is the commissioner's first major fine under the EU data regulation GDPR and was being watched closely by the rest of Europe as a potential landmark decision.

    The final figure of £20m has come as a shock to many who were expecting it to be closer to the eye-watering £183m initially proposed but it is still a significant moment for data privacy and GDPR. Other companies will look at the fine as a shape of things to come if they also fail to protect customers.

    In a post-Covid world, the ICO may not be as gentle.

    Our goal is to create a safe and engaging place for users to connect over interests and passions. In order to improve our community experience, we are temporarily suspending article commenting.

    What to Read Next

    • White Supremacist Had List of Feds to Kill and Doxx: Unsealed File

      The Daily Beast
    • Royal Mail postal workers will now collect parcels for delivery from your doorstep

      The Independent
    • Zuper COVID-19 Compliance pack helps companies like IKEA manage safe business operations in the new reality

      PR Newswire
    • MiX Telematics launches next generation, customizable driver scoring Software-as-a-Service module

      PR Newswire
    • Ralph Lauren to Offer Customized Packable Jackets

      WWD
    • Trump's closing pitch to voters admits that America has to be made 'great again' all over again

      Yahoo News
    • Demi Lovato warns that celebrity photos retouched to fit influencer aesthetics are harmful: 'Be careful'

      Yahoo Life
    • Is it a mop? Is it a vacuum? It's both—save $176 on this Roborock robot cleaner today

      Yahoo Life
    • Donald Trump Causes A Fuss Over Upcoming ‘60 Minutes’ Interview

      HuffPost
    • Hillary Clinton Shares Chilling Warning From 4 Years Ago: 'Speech For Everything'

      HuffPost
    • Anxieties rise about substantial delays — and Republican trickery — in election results

      Yahoo News
    • U.S. spacecraft touches asteroid surface for rubble grab

      Yahoo News Video
    • Defense Drone Antenna Market Forecast to 2027 - COVID-19 Impact and Global Analysis by Technology, Type, Frequency, and Application, and Geography

      GlobeNewswire
    • Report: Tax records show Trump tried to land China projects

      Associated Press
    • Biden's Social Security and SSI plan would lift 1.4 million out of poverty, study finds

      Yahoo Money
    • Outrage among Hindu groups as Kamala Harris's niece shares image of her photoshopped as goddess

      The Independent
    • How are there still undecided voters this late in the race?

      Yahoo News 360
    • Yahoo News/YouGov Poll: As COVID-19 cases soar, most Americans are either planning or considering a ‘normal’ Thanksgiving

      Yahoo News Video
    • Global Hot ICs Report 2020: A Market Analysis of Artificial Intelligence (AI), 5G, CMOS Image Sensors, and Memory Chips - ResearchAndMarkets.com

      Business Wire
    • Joe Biden Unveils Powerful New Ad Featuring One Of America’s Most Iconic Voices

      HuffPost
    • Ice Cube Responds After Eric Trump Shares Manipulated Photo Suggesting Rapper and 50 Cent Are Team Trump

      Complex
    • Elon Musk becomes Twitter laughingstock after Bolivian socialist movement returns to power

      Salon
    • Poll worker fired for turning away voters wearing BLM shirts

      Yahoo News Video
    • Tier-1 Telecom Service Provider in APAC Selects Allot HomeSecure to Provide Cyber-protection to Consumers

      GlobeNewswire
    • Yahoo News Network
    • Help
    • Privacy (Updated)
    • Suggestions
    • About our Ads
    • Terms (Updated)
    • Sitemap