British Airways owner IAG has revealed there may have been 185,000 more victims of its late summer data hack than previously thought.
On 6th September, after an initial investigation, IAG announced that details of about 380,000 customer transactions were stolen. British Airways’ chief executive, Alex Cruz, had described it as a “sophisticated, malicious criminal attack,” which took place between 21st August and 5th September.
Considerably worse
But since that announcement further investigations have found the data breach to be considerably worse than initially thought.
A statement from the company on Thursday read: “British Airways has been working continuously with specialist cyber forensic investigators and the National Crime Agency to investigate fully the data theft.”
The investigation, it said, has shown the hackers may have stolen additional personal data. It is now in the process of notifying the holders of 77,000 payment cards – not previously notified – that the name, billing address, email address, card payment information, including card number, expiry date and CVV, have potentially been compromised, and a further 108,000 without CVV.
British Airways added that the potentially impacted customers were those only making reward bookings between 21st April and 28th July, 2018, and who used a payment card.
The statement continued: “While we do not have conclusive evidence that the data was removed from British Airways’ systems, we are taking a prudent approach in notifying potentially affected customers, advising them to contact their bank or card provider as a precaution. Customers who are not contacted by British Airways by Friday 26th October at 5pm GMT do not need to take any action.”

In addition, British Airways said it now knows that fewer of the customers it originally announced were impacted. Of the 380,000 payment card details announced, 244,000 were affected.
“Crucially, we have had no verified cases of fraud,” a British Airways spokesperson said.
“We are very sorry that this criminal activity has occurred. As we have been doing, we will reimburse any customers who have suffered financial losses as a direct result of the data theft and we will be offering credit rating monitoring, provided by specialists in the field, to any affected customer who is concerned about an impact to their credit rating.”





