Wiser WebsitesWiser Websites

01582 931340

  • News
  • About
  • Home
  • Website Design
  • Services
  • Hosting
  • Work
  • Contact
Saturday, 13 July 2019 / Published in Website Design

CYBER SECURITY – How British Airways got stung

The scary part of all this is that the vulnerability in Modernizr is a well-known flaw, yet BA’s system had been waiting seven years for an update.

The ICO recently announced it was planning to fine the airline for a massive breach of customer data dating back to summer 2018, when users who booked flights through the BA app or website over the course of 12 weeks were directed to a fake website that filtered  off their personal details, such as usernames & passwords, credit card details as well as important information required for travelling on flights, including names and addresses.

“The ICO fine shows how serious some of BA’s failings were with its payment processing both on its website and its app,” says Andrew Dwyer, a cybersecurity researcher at the University of Oxford.

Hackers accessed the information of an estimated half a million people, according to the ICO, through a vulnerability in third-party JavaScript used on the BA website, exploited by a hacking group called Magecart.

Magecart are believed to have secreted 22 lines of code that diverted crucial details around payments to a separate website controlled by the criminals. The third-party piece of JavaScript, Modernizr, sent data to baways.com – a similar-sounding website to the official one, but out of the control of the airline.

The scary part of all this is that the vulnerability in Modernizr is a well-known flaw, yet BA’s system had been waiting seven years for an update.

BA had according to WIRED magazine’s Christopher Stokel-Walker not updated this system since 2012,  long after problems were known to exist.

“As a singular error it could be seen as fairly trivial – as it was one script that was compromised and used to exfiltrate data,” says Dwyer. “However, that it was not found for so long and that script had not been updated suggests a more systemic issue of IT governance at BA – meaning it is unlikely this is an isolated vulnerability. Effective monitoring would have picked up this quickly – not the three months it took BA.”

“Even today, its payment page still gives access to third-party scripts and does not add sufficient protections that would necessarily be expected to keep payment segmented from potential access from these third parties,” he adds.

This should come as a warning to businesses everywhere. The time of ignoring Data Protection and Cyber Security are well and truly over.

What you can read next

6 of the Best Underwater Restaurants
Cable Management
Cable Porn
GDPR: Information Commissioner’s Office follows up BA’s record fine with a £99 million fine for Marriott Hotels data security breach.

Recent Posts

  • The History of YouTube

    The rise and rise of YouTube continues, it has ...
  • National womens equality day – Women in tech

    International Women’s Day 2025 – Women in Tech:...
  • 6 Positive Impacts of Technology on Daily Life in 2025

    6 Positive Impacts of Technology on Daily Life ...
  • Spanish ‘beach body’ ad gets complaints over image used.

    A Spanish body confidence ad was published in J...
  • 7760

    What Is YouTube and How Can You Leverage Its Po...

Get updates and SEO advice

COMPANY

  • Frequently Asked Questions
  • Why Choose Wiser Websites
  • Why Choose WordPress
  • Website Consultancy
  • Charity Work

WEB DESIGN & OPTIMSATION

  • Search Engine Optimisation
  • Best Local Listing Sites
  • Business Listings & Maps
  • Website Analysis
  • Website Features

HOSTING & SECURITY

  • Hosting Platform Technologies
  • Frequently Asked Questions
  • SSL Certificates

FOLLOW US

SUBSCRIBE

Add your email to join our newsletter

TOP