Skip to content
Wednesday 22 July 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE
City PM

European business, markets and politics

FTSE 100
10,585.91
+0.58%
DAX
25,011.35
+0.66%
CAC 40
8,363.14
+0.28%
STOXX 50
6,285.63
+0.94%
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
More
GermanyFranceBankingAIEnergyFintechPropertyCapital Markets
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
  • DE
Tuesday 11 September 2018 1:07 pm

British Airways data breach: How hackers stole customers’ data

By: Joe Curtis

Add as a preferred source on Google

  British Airways’ breach last week was caused by the same group of hackers that targeted Ticketmaster, according to cyber security researchers.

The cyber attack resulted in 380,000 customers’ personal and financial details ending up in the hands of criminals, with the airline warning those affected to contact their banks and promising full compensation.

Read more: BA in data theft mess as 380,000 card payments 'compromised'

Cyber security firm Risk IQ quickly identified it as a website credit card so-called skimming attack, where hackers infiltrate third-party software embedded in other websites to copy details entered by unsuspecting users.

Today it pointed the finger at a hacking outfit known as Magecart, which was also blamed for a hack on Ticketmaster earlier this year affecting up to 40,000 customers.

But Risk IQ warned its latest attack was much more sophisticated.

Rather than targeting third-party software embedded into a website, which is a typical approach to online skimming, Risk IQ’s analysis found that Magecart compromised the site itself, copying and modifying BA’s code supporting payments to send the payment details unwitting travellers type in to its own server.

The app shared many similarities with the website, making it easy for hackers to adjust their technique to target travellers paying via their smartphones, too.

"This attack is a highly targeted approach compared to what we’ve seen in the past with the Magecart skimmer,” said Yonathan Klijnsma, head researcher at RiskIQ.

"This skimmer is attuned to how British Airways’ payment page is set up, which tells us that the attackers carefully considered how to target this site in particular."

The firm’s analysis found that Magecart operatives could have infiltrated BA’s site days before the hack began on 21 August. A web certificate on the attacker’s main server was issued on 15 August.

Rob Shapland, principle cyber security consultant at Falanx Group, said BA could have prevented the hack simply by tracking any changes to its website’s code.

Read more: BA boss promises compensation after data breach

“The malicious code that steals the credit card details was injected into the site and would change the source code, meaning that it would be relatively simple to flag up the difference as soon as it occurred,” he said.

“One thing we don't know at this time is how the code was inserted into the site, as this could mean that the hackers had further access to BA systems.​"

BA declined to comment, saying a criminal investigation remains underway.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Business
  • Tech
  • Transport & Infrastructure

Trending Articles

  • Exclusive: EQT to announce Emirates GBR SailGP deal

  • ‘Phenomenal waste of time’: Burnham slammed over plans to dismantle tech department

  • Will Ibai take home a Toast the City Award?

  • Calanda can give Graffard a third King George

  • Chance things Fall right for Sunshine and Commanche

More from City PM

  • London-listed healthcare services firm hit by cyberattack

    Markets
    Assura has been the subject of a ferocious bidding war for nearly six months
  • M&S to face shareholder grilling over cyber attack recovery

    Retail
    Marks and Spencer was one of three UK retailers to be targeted
  • U.K. Firms Make Cyber Resilience Measurable

    Business Wire
  • M&S chair: Tax and employment costs holding back Britain

    Retail
    Archie Norman, business leader, speaking at a corporate event wearing a suit and tie, engaging with the audience.
  • Rolls-Royce shares rise as Burnham pledges investment in British defence

    Politics
    Andy Burnham speaking at a press conference, wearing a suit and tie, addressing current political issues in Manchester.
  • ‘The problems didn’t begin with John Edwards’: Pressure grows for wider data watchdog overhaul

    Tech
    Offi
  • As it happened: FTSE 100 rises to defy tech gloom; oil creeps up on fresh Iran tensions

    Markets
    Donald Trump with hand on chin, appearing contemplative during a public event, wearing a suit and red tie.
  • British consultants face slowdown as corporate spending slumps

    Consulting
    London office workers collaborating on AI and tech projects, surrounded by computers and digital interfaces in a modern wo...
CityPM

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Business

  • Markets
  • Banking
  • Technology
  • Energy
  • Property
  • Fintech

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About City PM
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 City PM Ltd · Published by CityPM Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook