Risk

9/7/2018
11:00 AM
50%
50%

British Airways Issues Apology for Severe Data Breach

The airline "is deeply sorry" for its worst-ever cyberattack, which has affected 380,000 customers.

It's been a bumpy week for British Airways, which has apologized to 380,000 customers whose credit card information and other personal data was compromised in the worst cyberattack to hit the airline's website and app in the 20-plus years it has been online.

The breach was first detected on Wednesday, Sept. 5, when British Airways learned bookings made during the two weeks prior had been affected by cybercriminals. Between Aug. 21 and Sept. 5, attackers compromised 380,000 card payments and stole customers' names, physical and email addresses, and credit card numbers, expiration dates, and security codes.

BA chairman and chief executive Alex Cruz said the airline is "deeply sorry" for the attack, which he described as "very sophisticated" and "malicious," Reuters reports. Cruz did not describe how attackers gained access to the data, but said the carrier's encryption was not broken.

Read more details here.

 

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
DavidHamilton
50%
50%
DavidHamilton,
User Rank: Apprentice
12/3/2018 | 12:42:40 AM
Make it right, how?
The problem with security breaches like this is that information isn't as easily retrievable as you would think once it's leaked out. I reckon that the company would have to do a lot more than apologise to recapture all that lost consumer confidence at the end of the day.
Russia Hacked Clinton's Computers Five Hours After Trump's Call
Robert Lemos, Technology Journalist/Data Researcher,  4/19/2019
Tips for the Aftermath of a Cyberattack
Kelly Sheridan, Staff Editor, Dark Reading,  4/17/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-11378
PUBLISHED: 2019-04-20
An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files[]=../ directory traversal. It is possible for users to read arbitrary files and (potentially) access the supporting database, delete arbitrary files, access user passwords, or run arbitrary code.
CVE-2019-11372
PUBLISHED: 2019-04-20
An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
CVE-2019-11373
PUBLISHED: 2019-04-20
An out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
CVE-2019-11374
PUBLISHED: 2019-04-20
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
CVE-2019-11375
PUBLISHED: 2019-04-20
Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI.