Skip to content
Saturday 8 August 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE
MorningWire

European business, markets and politics

FTSE 100
10,901.09
+0.31%
DAX
26,319.45
+0.69%
CAC 40
8,714.93
+0.17%
STOXX 50
6,523.86
+0.33%
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
More
GermanyFranceBankingAIEnergyFintechPropertyCapital Markets
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
  • DE
Tuesday 11 September 2018 1:07 pm

British Airways data breach: How hackers stole customers’ data

By: Joe Curtis

Add as a preferred source on Google

  British Airways’ breach last week was caused by the same group of hackers that targeted Ticketmaster, according to cyber security researchers.

The cyber attack resulted in 380,000 customers’ personal and financial details ending up in the hands of criminals, with the airline warning those affected to contact their banks and promising full compensation.

Read more: BA in data theft mess as 380,000 card payments 'compromised'

Cyber security firm Risk IQ quickly identified it as a website credit card so-called skimming attack, where hackers infiltrate third-party software embedded in other websites to copy details entered by unsuspecting users.

Today it pointed the finger at a hacking outfit known as Magecart, which was also blamed for a hack on Ticketmaster earlier this year affecting up to 40,000 customers.

But Risk IQ warned its latest attack was much more sophisticated.

Rather than targeting third-party software embedded into a website, which is a typical approach to online skimming, Risk IQ’s analysis found that Magecart compromised the site itself, copying and modifying BA’s code supporting payments to send the payment details unwitting travellers type in to its own server.

The app shared many similarities with the website, making it easy for hackers to adjust their technique to target travellers paying via their smartphones, too.

"This attack is a highly targeted approach compared to what we’ve seen in the past with the Magecart skimmer,” said Yonathan Klijnsma, head researcher at RiskIQ.

"This skimmer is attuned to how British Airways’ payment page is set up, which tells us that the attackers carefully considered how to target this site in particular."

The firm’s analysis found that Magecart operatives could have infiltrated BA’s site days before the hack began on 21 August. A web certificate on the attacker’s main server was issued on 15 August.

Rob Shapland, principle cyber security consultant at Falanx Group, said BA could have prevented the hack simply by tracking any changes to its website’s code.

Read more: BA boss promises compensation after data breach

“The malicious code that steals the credit card details was injected into the site and would change the source code, meaning that it would be relatively simple to flag up the difference as soon as it occurred,” he said.

“One thing we don't know at this time is how the code was inserted into the site, as this could mean that the hackers had further access to BA systems.​"

BA declined to comment, saying a criminal investigation remains underway.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Business
  • Tech
  • Transport & Infrastructure

Trending Articles

  • WPP slashes jobs as revenue continues to fall

  • Liverpool owners tipped to sell – but not to Amazon boss Bezos – by former CEO

  • Revolut founder’s wealth set to balloon amid talks of share award at $500bn valuation

  • Starling plans to ‘come out swinging’ in diversification bid

  • As it happened: Stocks rise despite new tensions in Strait of Hormuz; Oil price climbs

More from Morning Wire

  • UK government probes OpenAI breach after ‘unprecedented’ hack

    Tech
    Sam Altman discussing OpenAIs ChatGPT advancements at a press conference, emphasizing AI innovation and future developments
  • London-listed healthcare services firm hit by cyberattack

    Markets
    Assura has been the subject of a ferocious bidding war for nearly six months
  • UK’s AI watchdog flags new OpenAI and Anthropic cyber alarms

    AI
    Smartphone displaying the Claude by Anthropic AI assistant app, showing the app icon and interface.
  • Accertify and Liminal Release First Empirical Study Proving Fraud-Cyber Convergence Works – and Defining How to Do It Right

    Business Wire
  • M&S to face shareholder grilling over cyber attack recovery

    Retail
    Marks and Spencer was one of three UK retailers to be targeted
  • Champions Cup rugby team hacked in ransom attack with player data at risk

    Sport Business
    Rugby player in a pink uniform running with the ball, pursued by an opponent in a black jersey.
  • Wasabi and Megaport Partner to Advance the Next Generation of AI and Cloud Infrastructure

    Business Wire
  • ‘Extremely dangerous’: AI warfare much bigger threat than LLM model advances, experts warn

    AI
    Swarm of AI-powered drones flying over a city skyline, symbolizing modern warfare and autonomous technology.
MorningWire

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Business

  • Markets
  • Banking
  • Technology
  • Energy
  • Property
  • Fintech

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About Morning Wire
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 Morning Wire Ltd · Published by Morning Wire Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook