Skip to content
Friday 24 July 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE
City PM

European business, markets and politics

FTSE 100
10,736.53
+0.92%
DAX
25,070.45
+1.24%
CAC 40
8,362.98
+0.77%
STOXX 50
6,273.23
+1.02%
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
More
GermanyFranceBankingAIEnergyFintechPropertyCapital Markets
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
  • DE
Thursday 25 October 2018 4:36 pm  |  Updated:  Tuesday 21 May 2019 4:21 pm

British Airways reveals a further 185,000 users affected in fresh data hack

NULL

British Airways owner International Airlines Group today said an investigation into September's data breach has revealed a further 185,000 users had been affected in an earlier hack on its website.

An internal investigation uncovered a second hack which showed the financial details of another 77,000 payment cards were potentially compromised, including their card number, expiry date and CVV, as well as a further 108,000 cards without the CVV.

The earlier breach affected British Airways customers making reward bookings between 21 April and 28 July this year using a payment card.

However the firm also revised down its initial estimates of customers originally identified in the breach on 6 September, from 380,000 to 244,000. The total number of users affected in both hacks now stands at 429,000.

The airline said it had not been notified of any verified cases of fraud as a result of the hack.

The firm said in a stock market filing: “While British Airways does not have conclusive evidence that the data were removed from its systems, it is taking a prudent approach in notifying potentially affected customers, advising them to contact their bank or card provider as a precaution.”

Matt Middleton-Leal, EMEA general manager for IT security firm Netwrix, said: "The ease at which the hackers were able to insert malicious code into the BA website is a significant concern. The type of attack, known as cross-site scripting, is not new in any way.

"It relies on a poorly designed website which can then be altered to harvest data for the hacker. If organisations do not test their public facing applications regularly and protect the data they capture and store these embarrassing leaks will continue."

 

Despite the news, shares in IAG closed more than three per cent up.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Business
  • Tech
  • Transport & Infrastructure

Related Topics

Trending Articles

  • BT braces for loss of 800,000 customers as it banks on fibre to keep turnaround ‘on track’

  • Regulator flags BDO’s ‘unacceptable’ audit issues for fifth year in a row 

  • Wise denied US banking licence in blow to expansion plans

  • Tax rises ‘guaranteed’ as Healey faces £22bn black hole from Burnham spending plans

  • ‘We are going to run out’: Mitie marks eleventh mega takeover of 2026

More from City PM

  • UK government probes OpenAI breach after ‘unprecedented’ hack

    Tech
    Sam Altman discussing OpenAIs ChatGPT advancements at a press conference, emphasizing AI innovation and future developments
  • London-listed healthcare services firm hit by cyberattack

    Markets
    Assura has been the subject of a ferocious bidding war for nearly six months
  • ‘The problems didn’t begin with John Edwards’: Pressure grows for wider data watchdog overhaul

    Tech
    Offi
  • Virgin Media slapped with £28m fine for stopping customers cancelling deals

    Telecoms
    Vans parked at a bustling city intersection surrounded by tall buildings and pedestrians, highlighting urban transportatio...
  • Expensify Expands Collaboration with Marqeta to Bring its Card Offering into Europe

    Business Wire
  • Exclusive: Nothing slashes jobs in cost-cutting push

    Tech
    Nothing Phone 1 showcasing its transparent back design and unique LED light interface, representing innovation in smartpho...
  • Farage quits to stand in ‘people versus establishment’ by-election

    Politics
    George Cottrell and Nigel Farage engaging in a conversation at a political event, both dressed in formal attire.
  • Tesco Mobile breaches £600m debt facility after reporting failure

    Telecoms
    Overhead view of a brightly lit Tesco store interior with shoppers, product aisles, and Clubcard Prices signage.
CityPM

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Business

  • Markets
  • Banking
  • Technology
  • Energy
  • Property
  • Fintech

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About City PM
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 City PM Ltd · Published by CityPM Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook