Go Back  FlyerTalk Forums > Miles&Points > Airlines and Mileage Programs > British Airways | Executive Club
Reload this Page >

The password for your "britishairways.com" account has appeared in a data leak...

Community
Wiki Posts
Search

The password for your "britishairways.com" account has appeared in a data leak...

Thread Tools
 
Search this Thread
 
Old Mar 29, 2022, 8:38 pm
  #1  
Moderator: British Airways Executive Club
Original Poster
 
Join Date: Nov 2010
Location: TPA/ABZ
Programs: BA Lifetime Gold. GGL/CCR.
Posts: 13,248
The password for your "britishairways.com" account has appeared in a data leak...

This popped up on my Safari Start Page for me today.

My British Airways password is complex and unique and stored in my 1Password account. I have not yet been able to track down the source of the leak as I don't use my email address as my username and most sites require a search based on the email address.

Has anyone else seen this something similar in the last few days?



I have changed my password.
golfmad is offline  
Old Mar 29, 2022, 8:50 pm
  #2  
FlyerTalk Evangelist
 
Join Date: Dec 2003
Location: Not here; there!
Programs: AA Lifetime Gold
Posts: 29,574
Originally Posted by golfmad
This popped up on my Safari Start Page for me today.

My British Airways password is complex and unique and stored in my 1Password account. I have not yet been able to track down the source of the leak as I don't use my email address as my username and most sites require a search based on the email address.

Has anyone else seen this something similar in the last few days?



I have changed my password.
Could this have been a phishing attempt? I see that the pop-up has a "re-secure your account" link.
pennineuk likes this.
guv1976 is offline  
Old Mar 29, 2022, 8:58 pm
  #3  
Moderator: British Airways Executive Club
Original Poster
 
Join Date: Nov 2010
Location: TPA/ABZ
Programs: BA Lifetime Gold. GGL/CCR.
Posts: 13,248
Originally Posted by guv1976
Could this have been a phishing attempt? I see that the pop-up has a "re-secure your account" link.
I don't think so. It's a security feature in Safari itself. That said, I didn't use their link but went to the real website and changed my password. When I logged in I could see all my account details, Avios and lifetime tier points which were all correct.
golfmad is offline  
Old Mar 29, 2022, 11:41 pm
  #4  
 
Join Date: Nov 2004
Programs: BA GGL, LH FTL
Posts: 3,578
You can check https://haveibeenpwned.com/ to see if your account has been included in data breaches.

If I were you I'd change that password. Even if it is complex, the fact that it showed up in a previous breach makes it less secure.
LCY8737 is offline  
Old Mar 30, 2022, 2:18 am
  #5  
1P
 
Join Date: Apr 2000
Location: LAX and LHR. UA lifetime Gold 1.9MM 1K , DL Gold Medallion, HHonors Gold, Marriott Gold, Avis President's Club
Posts: 3,592
Posts purporting to come from credit card issuers, banks and others claiming that you need to reconfirm your security details are an almost daily occurrence these days. This Safari example is just another one. The tricksters are now casting their nets wider in the hope that some people will be fooled. Utility companies, local council garden waste, your internet company..... you name it, someone has tried it.

The answer is to ignore and delete them, and certainly never to click on a link in such an email.
AJA_, roberto99 and HMPS like this.
1P is offline  
Old Mar 30, 2022, 2:40 am
  #6  
 
Join Date: Aug 2017
Programs: BAEC
Posts: 460
9 out of 10 calls to my landline are scams and a much higher proportion of all electronic communication, mostly caught by rules, filters and security software. It’s just how the world is sadly. However I think OP did the right thing - changing the password but not via the ”helpfully” provided link.
Ladyfliestheredwhiteandblues is offline  
Old Mar 30, 2022, 2:58 am
  #7  
 
Join Date: Jun 2014
Posts: 212
Originally Posted by guv1976
Could this have been a phishing attempt? I see that the pop-up has a "re-secure your account" link.
Originally Posted by golfmad
I don't think so. It's a security feature in Safari itself. That said, I didn't use their link but went to the real website and changed my password. When I logged in I could see all my account details, Avios and lifetime tier points which were all correct.
Yeah, the links in the Safari home page alerts like this take you to the site of the compromised account, so in this case britishairways.com to give you a little push to change your password.

I think that's really weird golfmad - if it's a 1Password generated password then it's going to be properly unique, so this means that there's been a leak of plaintext passwords from BA. They're not necessarily going to have the email stored next to them, but all the details I can find about the known BA data breach are that it included "customer details", nothing about passwords 😕
trolleymusic is offline  
Old Mar 30, 2022, 3:03 am
  #8  
 
Join Date: Sep 2020
Programs: BA Bronze :(
Posts: 63
I've just tried to get in this morning and can't get in the BAEC through the main site at all!

Safari does have this built in warning but the UI for could be improved massively by not putting in a suspicious link. Not sure how, maybe by telling you go to keychain and go to the change password page of the website instead of just the link.

As far as I know, the check doesn't align the username with your password, it just looks to see if that password has been in any of its leak sources anywhere, not necessarily against your username. For the security conscious, it doesn't pass/check full plain text passwords, I assume there's some cryptgraphic hashing or similar used. But the best course of action is what you've done and to just change your BA password to a new complex password.
JD1905 likes this.
ModestPointsCollector is offline  
Old Mar 30, 2022, 3:18 am
  #9  
formerly JackDann
 
Join Date: Oct 2017
Location: Northern Ireland
Posts: 1,657
Went to login this morning and also unable to do so... the Circus continues.
JD1905 is online now  
Old Mar 30, 2022, 3:26 am
  #10  
Ambassador, British Airways Executive Club, easyJet and Ryanair
 
Join Date: Sep 2011
Location: UK/Las Vegas
Programs: BA Gold (GGL/CCR)
Posts: 15,924
Originally Posted by JackDann
Went to login this morning and also unable to do so... the Circus continues.
I’ve logged in with no issue this morning.
Tobias-UK is offline  
Old Mar 30, 2022, 3:33 am
  #11  
 
Join Date: Sep 2020
Programs: BA Bronze :(
Posts: 63
Originally Posted by Tobias-UK
I’ve logged in with no issue this morning.
It appears to be working now, it failed a number of times just before 10am, the website asked me if i had an OnBusiness account at one point, and then another failed login it put up a message about an upgrade.
Tobias-UK and Oaxaca like this.
ModestPointsCollector is offline  
Old Mar 30, 2022, 3:33 am
  #12  
 
Join Date: Jul 2009
Location: E14, LON
Programs: Virtuoso TA; SELECT TA; BAEC Gold; Hilton Honors Diamond; IHG Plantinum Amb
Posts: 238
Originally Posted by ModestPointsCollector
It appears to be working now, it failed a number of times just before 10am, the website asked me if i had an OnBusiness account at one point, and then another failed login it put up a message about an upgrade.
Yes - exactly the same happened to be this morning
poplarflyer is offline  
Old Mar 30, 2022, 3:41 am
  #13  
formerly JackDann
 
Join Date: Oct 2017
Location: Northern Ireland
Posts: 1,657
Got in... but went to search for flights and got this.

"There is currently no access to your account while we upgrade our system. Please visit the information page to find out how this may affect you. We apologise for any inconvenience caused and thank you for your patience."

When I clicked the link to visit the information page I got a "Page not found" error.
JD1905 is online now  
Old Mar 30, 2022, 4:21 am
  #14  
 
Join Date: May 2016
Posts: 1,167
Originally Posted by JackDann
Got in... but went to search for flights and got this.

"There is currently no access to your account while we upgrade our system. Please visit the information page to find out how this may affect you. We apologise for any inconvenience caused and thank you for your patience."

When I clicked the link to visit the information page I got a "Page not found" error.
#METOO - but seems to be working now
babyg_wc is online now  
Old Mar 30, 2022, 4:22 am
  #15  
Moderator: British Airways Executive Club
Original Poster
 
Join Date: Nov 2010
Location: TPA/ABZ
Programs: BA Lifetime Gold. GGL/CCR.
Posts: 13,248
Originally Posted by LCY8737
You can check https://haveibeenpwned.com/ to see if your account has been included in data breaches.
Yes, that was the first site I looked at but the main search facility only checks against email addresses or phone numbers and my details are not listed. I am currently downloading the full set of passwords from that site in order to run a search there.

Originally Posted by LCY8737
If I were you I'd change that password. Even if it is complex, the fact that it showed up in a previous breach makes it less secure.
As I said in post 1 that was the first thing I did.
golfmad is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.