British Airways is facing £183 million fine for 2018 data breach
Monday, July 8, 2019
The UK Information Commissioner’s Office (ICO) wants British Airways to pay a £183.39 million (nearly $230 million) fine for failing to protect personal and financial information of approximately 500,000 of its customers.
“The £183 million fine does not really terminate legal ramifications of BA related to their website hack, other parties may still have valid claims against BA,” noted Ilia Kolochenko, founder and CEO of web security company ImmuniWeb.
“It is now important to determine whose negligence or misconduct ultimately caused or facilitated the breach. If BA was relying only on automated vulnerability scanning for a business critical application, a cybersecurity supplier who suggested such a reckless strategy – may be liable under certain circumstances and BA may crossclaim the damages. In any case, this is a gloomy reminder that web and mobile application security is essentially important, and if negligently disregarded – may cost hundreds of millions. Prompt reaction, investigation and rapid notice won’t be good enough to avoid formidable fines. Prevention is much better than cure from financial, reputational and operations standpoints.”
Criminal groups that fall under the Magecart umbrella have been plundering websites for years. Read Full Article
SC Media: British Airways first fined under GDPR, faces £183m fine for 2018 data breach
Security Boulevard: Unprotected Elasticsearch database exposes 2 billion user records from smart home devices