---
title: Hundreds of Thousands of British Airways Customers Affected in Massive Data Breach
description: The credit card data of thousands of British Airways customers has been compromised. The company has informed authorities and is in contact with affected customers. What went wrong and how could this have been prevented?
image: https://insights.comforte.com/hubfs/Foto_BA_Post.jpg
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![Foto_BA_Post](https://insights.comforte.com/hubfs/Foto_BA_Post.jpg)](https://insights.comforte.com/british-airways-data-breach)

[Felix Rosbach](https://insights.comforte.com/author/felix-rosbach) l Sep 13, 2018 l [Data Protection](https://insights.comforte.com/tag/data-protection), [Data Breaches](https://insights.comforte.com/tag/data-breaches)

# Hundreds of Thousands of British Airways Customers Affected in Massive Data Breach

We all book flights online. Usually, that is nothing you have to worry about. But recently, hackers have stolen sensitive customer data from 380,000 bookings with British Airways. Over the course of two weeks, hackers captured data from hundreds of thousands of credit cards of British Airways customers. As a result, the share price of BA parent company, International Airlines Group (IAG) has fallen by more than 3%.

British Airways began contacting affected customers immediately and the authorities have been informed, the airline said. They have already issued an apology to customers and plan to “compensate them for any financial hardship that they may have suffered”.

## What happened?

Criminals captured sensitive data in what Alex Cruz, Chairman and CEO of British Airways, has described as a “sophisticated, malicious attack”. The airline has yet to reveal how exactly the breach took place. The point of attack was the booking system on the internet and the British Airways app where customers made or adjusted their air travel plans.

In total, there have been 380,000 cases in the past two weeks, starting on the evening of 21 August until the evening of 5 September when the breach was discovered. The thieves were able to capture sensitive cardholder data such as names, addresses, e-mail addresses and credit card information, including credit card numbers, expiration dates and three-digit security codes. Travel details and passport data have not been stolen, according to the airline.

In the meantime, the data breakdown has been resolved and customers can safely resume use of the internet booking system, the airline says.

## What’s the takeaway?

It is very difficult to protect a network. In particular, a large enterprisewide network with thousands of endpoints, several websites and a huge Omni-channel marketing and e-commerce environment is nearly impossible to secure.

E-commerce makes the situation significantly more complicated. Customers are entering very confidential information, such as credit card numbers and booking details. On the one hand, you have to make sure that the system is user-friendly and ensure a positive customer experience, while on the other hand the system should be secure. This can be a delicate balancing act as added security measures can be an inconvenience to customers as they may negatively impact usability.

Furthermore, many companies aren‘t even aware that they’ve been breached until long after the fact. The average time it takes companies to discover a breach is 170 days. So while companies are obligated to report breaches within 72 hours of their discovery, if the breach isn’t actually discovered until half a year later, significant damage can be done before anyone finds out why or how. Thankfully, British Airways managed to notice the attack while it was still happening, but that is rarely the case.

But the question remains: was this data loss avoidable?

We know that organisations must take every step necessary to protect their customer’s data. Many companies protect their network with a layered approach using complex and effective firewalls, identity access management or intrusion detection systems. But all these countermeasures still aren’t a 100% guarantee that a breach won’t happen. Protecting the system at its core with a data-centric security strategy is the last line of defence to make sure that the data itself is protected and useless to potential attackers in the event of a breach.

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/british-airways-data-breach&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/british-airways-data-breach&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/british-airways-data-breach&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/british-airways-data-breach&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/british-airways-data-breach&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Is your organisation prepared?

Check out our [Enterprise Data Protection Portal](https://www.comforte.com/enterprise-data-protection/) to find out more about data-centric security.

### Related posts

![Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/hubfs/comforte%20AG_%20Reuse%20Reward_%20How%20Banks%20Can%20Safely%20Unlock%20the%20Value%20of%20Their%20Data_03.2025.png)

 Mar 12, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Payments Transformation](https://insights.comforte.com/tag/payments-transformation) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

The financial world is awash with data. But too few organizations are able to use it effectively. In [Bank Director’s *2025 Technology Survey*](https://www.bankdirector.com/wp-content/uploads/2025/09/2025TechReport-OpenVersion.pdf), one-third of US banking leaders cite an inability to harness data as a top technology challenge facing their...

[Read more](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

![Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/hubfs/comforte%20AG_Delivering%20a%20Secure%2c%20Trusted%20Foundation%20for%20Cloud%20Growth%20at%20LGT_01.2026.png)

 Jan 15, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

There’s a world of difference between retail and private banking. While the former is transactional and focused on the mass market, the latter is built on trust and personal relationships. That trust can be hard won, but is easily lost, especially...

[Read more](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

![Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/hubfs/comforte%20AG_Top%20Indicators%20You%20Have%20a%20Cybersecurity%20Problem_and%20What%20to%20Do%20About%20It.png)

 May 22, 2025 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Digital Enablement](https://insights.comforte.com/tag/digital-enablement)

### [Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

Data is both blessing and curse to the modern enterprise. Yes, when analyzed effectively it can surface intelligence to improve decision making, customer engagement, process efficiency and, ultimately, drive revenue. But it also represents a major...

[Read more](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>