British Airways fined £183m over computer theft of passenger data

British Airways had revealed the hack in September, just a few months after the European Union tightened data protection laws with the so-called General Data Protection Regulation (GDPR).

July 08, 2019 01:00 pm | Updated 09:15 pm IST - London (United Kingdom):

Emergency services attend a British Airways passenger plane after it had to make an emergency landing at Heathrow airport. early Friday May 24, 2013.

Emergency services attend a British Airways passenger plane after it had to make an emergency landing at Heathrow airport. early Friday May 24, 2013.

British Airways has been fined more than £183 million after computer hackers last year stole bank details from hundreds of thousands of passengers, its parent group IAG said Monday.

In a statement, IAG said the U.K. Information Commissioner’s Office intends to issue the airline with a penalty notice under the U.K. Data Protection Act, totalling £183.39 million ($229.7 million, 205 million euros).

The fine is equivalent to 1.5% of British Airways' turnover in 2017, IAG added.

IAG chief executive Willie Walsh said it would consider appealing the fine as it seeks "to take all appropriate steps to defend the airline's position vigorously".

British Airways CEO Alex Cruz said the airline was "surprised and disappointed" by the punishment.

"British Airways responded quickly to a criminal act to steal customers' data," he said in the statement.

"We have found no evidence of fraud/fraudulent activity on accounts linked to the theft. We apologise to our customers for any inconvenience this event caused," Mr. Cruz added.

British Airways had revealed the hack in September, just a few months after the European Union tightened data protection laws with the so-called General Data Protection Regulation (GDPR).

The stolen data comprised customer names, postal addresses, email addresses and credit card information.

However the 15-day breach, which was fixed on discovery, did not involve travel or passport details.

Following disclosure of the hack, British Airways promised to compensate affected customers and took out full-page adverts in the U.K. newspapers to apologise to passengers.

It had meanwhile described the mass theft as "a very sophisticated, malicious, criminal attack on our website".

IAG is the owner of five airlines, including also Aer Lingus, Iberia, Level and Vueling, none of which were affected by the hack.

GDPR establishes the key principle that individuals must explicitly grant permission for their data to be used.

The case for the new rules had been boosted by a scandal over the harvesting of Facebook users' data by Cambridge Analytica, a U.S.-British political research firm, for the 2016 U.S. presidential election.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.