FlyerTalk Forums

FlyerTalk Forums (https://www.flyertalk.com/forum/index.php)
-   British Airways | Executive Club (https://www.flyertalk.com/forum/british-airways-executive-club-446/)
-   -   [Updated] 2018 data breach : BA fined £20 million (https://www.flyertalk.com/forum/british-airways-executive-club/1977204-updated-2018-data-breach-ba-fined-20-million.html)

Starship73 Jul 8, 2019 12:21 am

[Updated] 2018 data breach : BA fined £20 million
 

Mod edit: to comply with rule 7, FT requires a summary so members can decide whether to click through to the linked article


The watchdog said a variety of information was "compromised" by poor security arrangements at the company, including log in, payment card, and travel booking details as well name and address information.

The watchdog said BA had co-operated with its investigation and made improvements to its security arrangements.

The penalty is divided up between the other European data authorities, while the money that comes to the ICO goes directly to the Treasury.

It is up to individuals to claim money from BA, which provided no information on whether any compensation had been paid.

BA has 28 days to appeal. Willie Walsh, chief executive of IAG, said British Airways would be making representations to the ICO.

rapidex Jul 8, 2019 12:24 am

What will happen to Alex's bonus now?

rockflyertalk Jul 8, 2019 12:31 am


Originally Posted by rapidex (Post 31280234)
What will happen to Alex's bonus now?

It will go up of course :D

Misco60 Jul 8, 2019 12:31 am

British Airways says it's "surprised and disappointed" by the fine. Much as many of us were by the data breach and the subsequent indifference that BA showed towards the affected customers.

acucobol Jul 8, 2019 12:32 am

Good news for the class action lawsuit?

u01sss3 Jul 8, 2019 12:41 am

Any fine will probably just be passed onto us. Probably bad news.

Oaxaca Jul 8, 2019 12:49 am

BA fined £183m for 2018 data breach by UK ICO
 

https://www.bbc.co.uk/news/business-48905907

BA has been handed a record fine by the UK Information Commissioner’s Office for the 2018 data breach. Given that the previous record was £500k (according to the BBC), £183m is a huge statement.

BA/IAG has already said it will appeal, will be interesting to see what the ICO’s reasons are for the size of the fine.

Mods - I know there are existing threads on this, so feel free to merge if you don’t think this merits a separate thread.

13901 Jul 8, 2019 12:51 am

...and to think Alex was saying, at staff briefings, that "we won't be fined".

Yet another stirling success of IAG's Group IT strategy.

Flexible preferences Jul 8, 2019 12:52 am

Yes, the reasons would be helpful. This does seem very large, especially if BA cooperated fully.

colm Jul 8, 2019 12:59 am

Good. A few more of these and firms will start taking information security seriously.

muscat Jul 8, 2019 1:04 am


Originally Posted by u01sss3 (Post 31280277)
Any fine will probably just be passed onto us. Probably bad news.

With 45 million passengers per year, it’s only an extra £4 on every ticket. I do wonder what the point of these massive fines are when it is easy for a major company to pass the (minor) cost on to a large number of consumers. Surely better to fine board members or executives.

Sailbot3310 Jul 8, 2019 1:04 am

Who does the penalty money go to? Those affected?

I dropped out the lawsuit as I had no faith in SPG Law, I hope that isn't something I will come to regret!

Misco60 Jul 8, 2019 1:05 am

The ICO website offers further information about the fine.


The ICO’s investigation has found that a variety of information was compromised by poor security arrangements at the company, including log in, payment card, and travel booking details as well name and address information.

Information Commissioner Elizabeth Denham said: “People’s personal data is just that – personal. When an organisation fails to protect it from loss, damage or theft it is more than an inconvenience. That’s why the law is clear – when you are entrusted with personal data you must look after it. Those that don’t will face scrutiny from my office to check they have taken appropriate steps to protect fundamental privacy rights.”

thebigben Jul 8, 2019 1:05 am

I love how BA is trying to make us believe that a simple XSS attack is "sophisticated".

Maybe I should wear a tuxedo next time I practice my penetration testing skills. Then I'd be sophisticated.

Cw novice Jul 8, 2019 1:06 am

Will be interesting to see if this has any effect on AC's position. My only hope would be that frontline staff aren't made to bear the brunt of management mistakes.


All times are GMT -6. The time now is 8:30 pm.


This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.