News: 1602850504

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

British Airways fined £20m for Magecart hack that exposed 400k folks' credit card details to crooks

(2020/10/16)


British Airways is to pay a £20m data protection fine after its 2018 Magecart hack – even though the Information Commissioner’s Office discovered the airline had been saving credit card details in plain text since 2015.

The fine, announced this morning by the UK's data watchdog, is almost exactly at the reduced £19.8m level that BA parent company the International Airlines Group had [1]expected back in August .

“The failures are especially serious in circumstances where it is unclear whether or when BA itself would ever have detected the breach,” thundered the ICO today. It also condemned BA’s claims during fine negotiations that credit card data breaches are “an entirely commonplace phenomenon” and “an unavoidable fact of life”.

The airline's spokesman told The Register : “We alerted customers as soon as we became aware of the criminal attack on our systems in 2018 and are sorry we fell short of our customers’ expectations. We are pleased the ICO recognises that we have made considerable improvements to the security of our systems since the attack and that we fully co-operated with its investigation.”

British Airways’ internal payments systems were accessed by malicious people in June 2018, [2]as we reported at the time . Some 380,000 people’s credit and debit card details were stolen as a result.

Alarmingly, the ICO’s redacted fine notice published today ( [3]PDF ) revealed not only that the airline was compromised through a Citrix vulnerability but that it had been saving card details without any encryption at all – a huge no-no.

No MFA and plain text domain admin creds

The attackers began by compromising a BA network account issued to an employee of cargo-handling firm Swissport. That employee, based in Trinidad and Tobago, did not use multi-factor authentication (MFA) and the airline didn’t require it. Although the ICO report was heavily redacted at this point, the attacker then entered a Citrix environment and was able to escape from it onto the wider BA network, having “successfully copied a number of tools into the Citrix environment from outside the network.”

While carrying out network reconnaissance, the attackers hit the jackpot: the username and password for a Windows domain administrator account, “stored in plain text, in a folder on the server”.

The miscreants also found a database admin username and password later in their spree.

Although their next steps were redacted out of the report, the attackers eventually gained access to server logs that contained plaintext details of payment cards.

The ICO said: “The logging and storing of these card details (including, in most cases, CVV numbers) was not an intended design feature of BA’s systems… it was a testing feature that was only intended to operate when the systems were not live, but which was left activated when the systems went live.” Those logs were stored for three months.

From there, the attackers discovered source code for the BA website and [4]planted a card skimmer on the payments page used by the general public . Infosec firm RiskIQ reckoned, back in 2018, that the hack was the work of the Magecart payments theft gang.

Part of BA’s mitigation included deploying Crowdstrike’s Falcon tool across its systems.

Fine is 11 per cent of original penalty

Information Commissioner Elizabeth Denham [5]floated a £183m fine in July last year , saying at the time: “People's personal data is just that – personal. When an organisation fails to protect it from loss, damage or theft it is more than an inconvenience. That’s why the law is clear – when you are entrusted with personal data you must look after it. Those that don’t will face scrutiny from my office to check they have taken appropriate steps to protect fundamental privacy rights.”

As BA and IAG’s lawyers made representations to get the fine reduced, the COVID-19 pandemic struck – and as the ICO stopped enforcing data protection laws in the early part of 2020, it [6]started issuing [7]deadline extensions to BA .

The data watchdog said the fine had been reduced by £4m to take BA’s coronavirus financial situation into account, justifying this by pointing to IAG revenues in excess of £12bn in FY2017 – long before the pandemic tore the heart and lungs out of the air travel industry. COVID-19 and resulting government prohibitions have [8]forced the premature retirement of BA's iconic Boeing 747 fleet .

The fine reflects IAG’s H1 CY2020 [9]loss (PDF) of 1.9 billion euros, and the fact that the airline group has had to mortgage “old and new aircraft” to raise another 2.2bn euros in cash with which to ride out government travel bans linked to COVID-19.

BA's sprawling IT estate, interfacing with multiple third parties all over the world, has a [10]reputation for falling over at inconvenient moments . Such problems aren't helped when [11]incompetent contractors play "let's pull all the levers" with data centre power supplies. ®

Get our [12]Tech Resources



[1] https://www.theregister.com/2020/08/05/marriott_starwood_gdpr_fine_british_airways/

[2] https://www.theregister.com/2018/09/06/british_airways_hacked/

[3] https://ico.org.uk/media/action-weve-taken/mpns/2618421/ba-penalty-20201016.pdf

[4] https://www.theregister.com/2018/09/11/british_airways_website_scripts/

[5] https://www.theregister.com/2019/07/08/ico_threatens_ba_with_huge_fine_for_huge_data_loss/

[6] https://www.theregister.com/2020/01/13/ico_british_airways_marriott_fines_delayed/

[7] https://www.theregister.com/2020/04/06/ico_data_protection_fines_ba_marriott_hack_postponed/

[8] https://www.theregister.com/2020/07/17/british_airways_747_axed/

[9] https://www.iairgroup.com/~/media/Files/I/IAG/documents/interim-management-statement-for-the-six-months-to-june-30-2020.pdf

[10] https://www.theregister.com/2018/07/19/amadeus_british_airways_outage_load_sheet/

[11] https://www.theregister.com/2017/06/02/british_airways_data_centre_configuration/

[12] https://whitepapers.theregister.com/

wyatt

I hope that, if their insurance company is approached to cover the fine they give them the finger. To have user credentials saved in files like that is one of the 'unforgivables'.

one of the 'unforgivables'

Mike 137

Very common though. It was the prime cause of the massive scale of the Equifax breach of 2017.

Reduce the fine or ..

macjules

1) we will start sacking flight crew. Oh wait, we already starting doing that.

2) we will have to sell one of our islands. Oh wait, we’re not Virgin Ontheridiculous.

Anonymous Coward

I'm not aware of any other companies getting their legal fines reduced because of Coronavirus....why should BA be an exception? Especially since the event they're being penalised for happened LONG before Covid-19 struck...

Shameful

NeilPost

Absolutely Fucking shameful of the ICO and makes them look ineffectual pussies when it comes to enforcement.

Take the £20m as a down payment and defer the rest of the fine until BA turn around - say 2025 - and bust their ass then... rather than getting away effectively Scot-free and laughing their socks off. The fine was only delayed as they appealed and appealed against it.

The ICO chair should resign.

Anonymous Coward

Probably something to do with the ICO's legal budget being ~£2m/year, and BA's being substantially higher, thus this being a pragmatic solution - find the upper of end of what BA are willing to pay, or be dragged through the courts with legal challenges until no-one cares. :(

NeilPost

£20m is fuck all.

A £100m settlement would have been equitable... £20m now, and the rest paid off in instalments reflective of BA’s recovery/financial performance.... like say the boards remuneration package.

Nasty airline.

—

Watch Marriott pled poverty next.

Oh Matron!

I'm expecting Alex Cruz to have the same meteoric rise in Govt as Dido Harding, captain of another hack...

NeilPost

Don’t forget Willie Walsh.

He’s on the lookout for a new challenge having left IAG in a staff-bloodbath blaze of ignomany that should fit in well with BoJo’s government of fuckwits.

Halfmad

They should be forced to display a warning on any checkout pages for 5 years stating they have screwed up the past and that consumers should consider carefully before spending with them.

Unfortunately

Mike 137

This is the maximum fine the ICO can impose by law. The [1]draft statutory guidance on its regulatory action states that the Higher Maximum Amount (theoretically 4% of global annual turnover or 20M whichever is greater) is capped at 20M in the UK, although the guidance refers to Euros not GB pounds, which is going to be fun from January 1st..

Rather invalidates the purpose of the alternative.

[1] https://ico.org.uk/media/about-the-ico/consultations/2618333/ico-draft-statutory-guidance.pdf

Re: Unfortunately

viscount

That does seems strange: it means the GBP 20m penalty is higher than their permitted maximum of EUR 20m.

Re: Unfortunately

EnviableOne

no its not

the limit is 2% of global turnover of the undertaking (in this case IAG) in the year previous to the offence, or 20 million euros, whichever greater

the UK legislation translates the 20 million euro to 17 Million pounds

22,880 million euro in year to dec 2017 so 4% of that makes 915 million euro

so their initial fine of 189miliion pounds was well short of this, and considerably less than the 700million euro they returned to shareholders in that year, as a special dividend, on top of the standar 600Million euro normal one

Re: Unfortunately

NeilPost

I think the £193m levied was reflective of this.

You are talking British Airways/IAG ... not plucky small players like LoganAir.

Like I said above, take the £20m as a down payment and defer the rest for a few years and they can pay in instalments tied to company recovery/performance goals.No board ‘performance’ (sic) bonuses until all paid off.

Cynic_999

Pragmatism. If a company is in such financial difficulty that the fine will massively increase the number of job losses, you have to ask yourself who ends up being punished - and is that a just or fair result? Perhaps instead of reducing the fine, it should be deferred or taken in installments as a percentage of profits every year until paid.

If the fine is big enough that it is likely to result in the company going bust before it could raise that much money, it's a pointless exercise anyway and the main losers are the innocent employees.

Maybe better would be to make the fine much smaller but have the directors pay it personally rather than coming from the company account. I suspect that if the directors were to be fined £2 million it would have a far greater effect on their desire to ensure it doesn't happen again than fining the company £20 million.

osakajin

What do you expect. Fairness and justice.

Doctor Syntax

"the airline had been saving credit card details in plain text since 2015."

Presumably this is going to be subject to a whole lot of other actions from financial regulators and credit card companies.

viscount

They were saving the CVV too which seems like a basic error. No idea why.

Anonymous Coward

which seems like a basic error

Not to mention being a direct violation of PCI-DSS rules.

Who will finally pay for the £20M fine...

circusmole

...That's right - the customers! It's obvious that they will just load up their prices to recover the £20M, plus a little bit extra for their trouble, and there you go.

This has always been the case with this fines to the big companies, it's always the customer that pays in the end. There is, presumably, someone responsible for the security of customer data and someone accountable when they do not do their job properly. It is this person that should be held to account and personally fined and/or jailed. Typically this would be a board member.

Of course this will never happen, but I can dream.

Re: Who will finally pay for the £20M fine...

Anonymous Coward

Not the customers, by the time people start flying again, BA will have gone bankrupt. Unless our Glorious Leadership decides to chop down a few extra trees, print a few billion GBP more, give it away. We're fucked anyway, so let's party while we can!

Re: Who will finally pay for the £20M fine...

Anonymous Coward

Alternative solution to (expensive) flying: container ships. Punch a few holes, hang some hammocks, bring your own device and food, and voila, you can fit a good few people in them ships. What's a few days' delay, when you're unemployed anyway. Perhaps they need some offshore call centres off India? :)

British Airways fined £20m for Magecart hack

Anonymous Coward

click here to complete a voucher form...

NO TEETH

EnviableOne

The ICO has none, PCI have none, either that or they are refusing to use them.

This is a major breach of both GDPR and PCI-DSS, and neither regulator took any usefull enforcement action.

There should be binding conditions on IAG and BA, and they should have restrictions on their payment processing (requiring step-up authorisation)

They should also be required to be audited by the ICO to identify any othee shoddy practices...

If rash develops, discontinue use.