{"id":22026,"date":"2020-10-18T06:33:18","date_gmt":"2020-10-18T06:33:18","guid":{"rendered":"http:\/\/www.banglanewsus.com\/english\/?p=22026"},"modified":"2020-10-18T06:33:18","modified_gmt":"2020-10-18T06:33:18","slug":"british-airways-fined-20m-over-data-breach","status":"publish","type":"post","link":"https:\/\/www.banglanewsus.com\/english\/2020\/10\/18\/british-airways-fined-20m-over-data-breach\/","title":{"rendered":"British Airways fined \u00a320m over data breach"},"content":{"rendered":"<div class=\"css-uf6wea-RichTextComponentWrapper e1xue1i82\" data-component=\"text-block\">\n<div class=\"css-83cqas-RichTextContainer e5tfeyi2\">\n<p><b class=\"css-14iz86j-BoldText e5tfeyi0\">British Airways has been fined \u00a320m ($26m) by the Information Commissioner&#8217;s Office (ICO) for a data breach which affected more than 400,000 customers.<\/b><\/p>\n<\/div>\n<\/div>\n<div class=\"css-uf6wea-RichTextComponentWrapper e1xue1i82\" data-component=\"text-block\">\n<div class=\"css-83cqas-RichTextContainer e5tfeyi2\">\n<p>The breach took place in 2018 and affected both personal and credit card data.<\/p>\n<\/div>\n<\/div>\n<div class=\"css-uf6wea-RichTextComponentWrapper e1xue1i82\" data-component=\"text-block\">\n<div class=\"css-83cqas-RichTextContainer e5tfeyi2\">\n<p>The fine is considerably smaller than the \u00a3183m that the ICO originally said it intended to issue back in 2019.<\/p>\n<\/div>\n<\/div>\n<div class=\"css-uf6wea-RichTextComponentWrapper e1xue1i82\" data-component=\"text-block\">\n<div class=\"css-83cqas-RichTextContainer e5tfeyi2\">\n<p>It said &#8220;the economic impact of Covid-19&#8221; had been taken into account.<\/p>\n<\/div>\n<\/div>\n<div class=\"css-uf6wea-RichTextComponentWrapper e1xue1i82\" data-component=\"text-block\">\n<div class=\"css-83cqas-RichTextContainer e5tfeyi2\">\n<p>However, it is still the largest penalty issued by the ICO to date.<\/p>\n<\/div>\n<\/div>\n<div class=\"css-uf6wea-RichTextComponentWrapper e1xue1i82\" data-component=\"text-block\">\n<div class=\"css-83cqas-RichTextContainer e5tfeyi2\">\n<p>The incident took place when BA&#8217;s systems were compromised by its attackers, and then modified to harvest customers&#8217; details as they were input.<\/p>\n<\/div>\n<\/div>\n<div class=\"css-uf6wea-RichTextComponentWrapper e1xue1i82\" data-component=\"text-block\">\n<div class=\"css-83cqas-RichTextContainer e5tfeyi2\">\n<p>It was two months before BA was made aware of it by a security researcher, and then notified the ICO.<\/p>\n<\/div>\n<\/div>\n<div class=\"css-uf6wea-RichTextComponentWrapper e1xue1i82\" data-component=\"unordered-list-block\">\n<div class=\"css-83cqas-RichTextContainer e5tfeyi2\">\n<div class=\"css-1pzprxn-BulletListContainer e5tfeyi3\">\n<ul role=\"list\">\n<li><a class=\"css-yidnqd-InlineLink e1no5rhv0\" href=\"https:\/\/www.bbc.co.uk\/news\/technology-45446529\">How did hackers get into British Airways?<\/a><\/li>\n<li><a class=\"css-yidnqd-InlineLink e1no5rhv0\" href=\"https:\/\/www.bbc.co.uk\/news\/uk-england-london-45440850\">BA boss apologises for data breach<\/a><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"css-uf6wea-RichTextComponentWrapper e1xue1i82\" data-component=\"text-block\">\n<div class=\"css-83cqas-RichTextContainer e5tfeyi2\">\n<p>The data stolen included log in, payment card and travel booking details as well name and address information.<\/p>\n<\/div>\n<\/div>\n<div class=\"css-uf6wea-RichTextComponentWrapper e1xue1i82\" data-component=\"text-block\">\n<div class=\"css-83cqas-RichTextContainer e5tfeyi2\">\n<p>A subsequent investigation concluded that sufficient security measures, such as multi-factor authentication, were not in place at the time.<\/p>\n<\/div>\n<\/div>\n<div class=\"css-uf6wea-RichTextComponentWrapper e1xue1i82\" data-component=\"text-block\">\n<div class=\"css-83cqas-RichTextContainer e5tfeyi2\">\n<p>The ICO noted that some of these measures were available on the Microsoft operating system that BA was using at the time.<\/p>\n<\/div>\n<\/div>\n<div class=\"css-uf6wea-RichTextComponentWrapper e1xue1i82\" data-component=\"text-block\">\n<div class=\"css-83cqas-RichTextContainer e5tfeyi2\">\n<p>&#8220;When organisations take poor decisions around people&#8217;s personal data, that can have a real impact on people&#8217;s lives. The law now gives us the tools to encourage businesses to make better decisions about data, including investing in up-to-date security,&#8221; said Information Commissioner Elizabeth Denman.<\/p>\n<\/div>\n<\/div>\n<div class=\"css-uf6wea-RichTextComponentWrapper e1xue1i82\" data-component=\"text-block\">\n<div class=\"css-83cqas-RichTextContainer e5tfeyi2\">\n<p>British Airways said it had alerted customers as soon as it had found out about the attack on its systems.<\/p>\n<\/div>\n<\/div>\n<div class=\"css-uf6wea-RichTextComponentWrapper e1xue1i82\" data-component=\"text-block\">\n<div class=\"css-83cqas-RichTextContainer e5tfeyi2\">\n<p>&#8220;We are pleased the ICO recognises that we have made considerable improvements to\u202fthe security of our systems since the attack and that we fully co-operated with its investigation,&#8221; said a spokesman.<\/p>\n<\/div>\n<\/div>\n<div class=\"css-uf6wea-RichTextComponentWrapper e1xue1i82\" data-component=\"text-block\">\n<div class=\"css-83cqas-RichTextContainer e5tfeyi2\">\n<p>Data protection officer Carl Gottlieb said that in the current climate, \u00a320m was a &#8220;massive&#8221; fine.<\/p>\n<\/div>\n<\/div>\n<div class=\"css-uf6wea-RichTextComponentWrapper e1xue1i82\" data-component=\"text-block\">\n<div class=\"css-83cqas-RichTextContainer e5tfeyi2\">\n<p>&#8220;It shows the ICO means business and is not letting struggling companies off the hook for their data protection failures,&#8221; he said.<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>British Airways has been fined &pound;20m ($26m) by the Information Commissioner&rsquo;s Office (ICO) for a data breach which affected more than 400,000 customers. The breach took place in 2018 and affected both personal and credit card data. The fine is considerably smaller than the &pound;183m that the ICO originally said it intended to issue back in 2019. It said &ldquo;the economic impact of Covid-19&rdquo; had been taken into account. However, it is still the largest penalty issued by the ICO to date. The incident took place when BA&rsquo;s systems were<\/p>\n","protected":false},"author":4,"featured_media":22027,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[30,31],"tags":[],"_links":{"self":[{"href":"https:\/\/www.banglanewsus.com\/english\/wp-json\/wp\/v2\/posts\/22026"}],"collection":[{"href":"https:\/\/www.banglanewsus.com\/english\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.banglanewsus.com\/english\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.banglanewsus.com\/english\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.banglanewsus.com\/english\/wp-json\/wp\/v2\/comments?post=22026"}],"version-history":[{"count":1,"href":"https:\/\/www.banglanewsus.com\/english\/wp-json\/wp\/v2\/posts\/22026\/revisions"}],"predecessor-version":[{"id":22028,"href":"https:\/\/www.banglanewsus.com\/english\/wp-json\/wp\/v2\/posts\/22026\/revisions\/22028"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.banglanewsus.com\/english\/wp-json\/wp\/v2\/media\/22027"}],"wp:attachment":[{"href":"https:\/\/www.banglanewsus.com\/english\/wp-json\/wp\/v2\/media?parent=22026"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.banglanewsus.com\/english\/wp-json\/wp\/v2\/categories?post=22026"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.banglanewsus.com\/english\/wp-json\/wp\/v2\/tags?post=22026"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}