Skip to content
CityAM
Main navigation
  • News
    • News
      • Latest Business News
      • Economics
      • Politics
      • Tech
      • Banking
      • FTSE 100 Live
      • Retail
      • Insurance
      • Legal
      • Property
      • Transport
      • Markets
    • From our partners
      • AON
      • Bayes Business School
      • Canada BIDs
      • Central London Alliance CIC
      • Destination City
      • Halkin
      • Olympia
      • Inside Saudi
      • Tottenham Hotspur Stadium
      • Santander X
      • YEAR SIX Dividend
    • Featured

      Bank of England to ‘tolerate slow return’ to inflation target as interest rates held

      Bank of England Governor Andrew Bailey said cited several indicators that the labour market was softening.

      Submit a story

      Tell us your story.

      Submit
  • Opinion
  • Sport
    • Latest Sports News
      • Sport
      • Sport Business
    • From our partners
      • The Morning Briefing: SBS x CityAM
      • Aramco Team Series
      • LIV Golf
    • Featured

      Yas Queen’s: Why HSBC Championships expansion has been a smash for business

      Getty Images illustration depicting diverse business professionals collaborating in a modern office setting, reflecting te...

      Submit a story

      Tell us your story.

      Submit
  • Life&Style
    • Life&Style
      • Life&Style
      • Toast the City Awards
      • The Magazine
      • Travel
      • Culture
      • Motoring
      • Wellness
      • The RED BULLETiN
      • Do it with Shared Ownership
      • Media Speak Hub
    • Featured

      This Peugeot 205 GTI is the car you remember from your teenage years

      Vintage Peugeot 205 driving on a scenic road, showcasing classic design and compact size for a news feature on iconic cars

      Submit a story

      Tell us your story.

      Submit
  • Investec
  • Events
  • Latest Paper
Tuesday 11 September 2018 1:07 pm

British Airways data breach: How hackers stole customers’ data

By: Joe Curtis

Add as a preferred source on Google

  British Airways’ breach last week was caused by the same group of hackers that targeted Ticketmaster, according to cyber security researchers.

The cyber attack resulted in 380,000 customers’ personal and financial details ending up in the hands of criminals, with the airline warning those affected to contact their banks and promising full compensation.

Read more: BA in data theft mess as 380,000 card payments 'compromised'

Cyber security firm Risk IQ quickly identified it as a website credit card so-called skimming attack, where hackers infiltrate third-party software embedded in other websites to copy details entered by unsuspecting users.

Today it pointed the finger at a hacking outfit known as Magecart, which was also blamed for a hack on Ticketmaster earlier this year affecting up to 40,000 customers.

But Risk IQ warned its latest attack was much more sophisticated.

Rather than targeting third-party software embedded into a website, which is a typical approach to online skimming, Risk IQ’s analysis found that Magecart compromised the site itself, copying and modifying BA’s code supporting payments to send the payment details unwitting travellers type in to its own server.

The app shared many similarities with the website, making it easy for hackers to adjust their technique to target travellers paying via their smartphones, too.

"This attack is a highly targeted approach compared to what we’ve seen in the past with the Magecart skimmer,” said Yonathan Klijnsma, head researcher at RiskIQ.

"This skimmer is attuned to how British Airways’ payment page is set up, which tells us that the attackers carefully considered how to target this site in particular."

The firm’s analysis found that Magecart operatives could have infiltrated BA’s site days before the hack began on 21 August. A web certificate on the attacker’s main server was issued on 15 August.

Rob Shapland, principle cyber security consultant at Falanx Group, said BA could have prevented the hack simply by tracking any changes to its website’s code.

Read more: BA boss promises compensation after data breach

“The malicious code that steals the credit card details was injected into the site and would change the source code, meaning that it would be relatively simple to flag up the difference as soon as it occurred,” he said.

“One thing we don't know at this time is how the code was inserted into the site, as this could mean that the hackers had further access to BA systems.​"

BA declined to comment, saying a criminal investigation remains underway.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Business
  • Tech
  • Transport & Infrastructure

Trending Articles

  • More Big Four blues as Deloitte plans to slash UK audit roles

  • Rathbones to suspend thousands of client account inflows after FCA probe deals £530m blow

  • Rolls-Royce shares surge as SMR unit bags multi-billion pound Swedish nuclear contract

  • FTSE 100 Live: Stocks sink further as interest rates held; Oil falls as ‘economic catastrophe’ avoided

  • Baillie Gifford in line for Anthropic windfall just months after £3.6bn SpaceX bonanza

More from CityAM

  • Top spook says Russia ‘relentlessly targeting’ UK infrastructure 

    Tech
    GCHQ headquarters at dusk with illuminated windows, showcasing the iconic circular building amidst a vibrant evening sky.
  • The Debate: Should CEOs be held personally accountable for cyberattacks?

    Opinion
    Evil-looking keyboard symbolizing cybersecurity threats and hacking risks in a digital landscape.
  • M&S profit slumps in fallout from cyber attack

    Retail
    Microsoft headquarters building with company logo prominently displayed against a clear blue sky
  • M&S eyes up Brits’ weekly shops as food arm set to expand

    Retail
    News article image related to a general topic, possibly showcasing a relevant scene or event for a business website.
  • Gambit Cyber Launches Vizier AI – An Autonomous Security Intelligence Workspace for Continuous Exposure Management

    Business Wire
  • IMF warns AI cyberattacks could trigger global financial crisis

    Tech
    The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
  • UK ministers tell UK businesses to ‘step up’ cyber defences

    Tech
    The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
  • Iran and Russia to target Fifa World Cup, threat experts say

    Sport Business
    GettyImages 2277625963 shows a significant event in the news, capturing key figures and moments relevant to current global...

CityAM Canada — business, markets and opinion for Canadian readers.

Sections

  • Business
  • Markets
  • Tech
  • AI
  • Economics
  • Opinion
  • Cities

Company

  • About
  • Contact

Legal

  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 CityAM Canada. All rights reserved.
Terms · Privacy · Cookies