Skip to content
Search

Latest Stories

Submit Guest Post

British Airways faces $230m fine over last year’s data theft

BRITISH AIRWAYS-owner IAG is facing a record $230 million fine for the theft of data from 500,000 customers from its website last year under tough new data-protection rules policed by the UK's Information Commissioner's Office (ICO).

The ICO proposed a penalty of £183.4 million, or 1.5 per cent of British Airways' 2017 worldwide turnover, for the hack, which it said exposed poor security arrangements at the airline.


BA indicated that it planned to appeal against the fine, the product of European data protection rules, called GDPR, that came into force in 2018.

They allow regulators to fine companies up to four per cent of their global turnover for data-protection failures.

The attack involved traffic to the British Airways website being diverted to a fraudulent site, where customer details such as log in, payment card and travel booking details as well as names and addresses were harvested, the ICO said.

Information Commissioner Elizabeth Denham said: "People's personal data is just that- personal.

"When an organisation fails to protect it from loss, damage or theft it is more than an inconvenience. That's why the law is clear – when you are entrusted with personal data you must look after it."

BA's chairman and chief executive Alex Cruz said he was "surprised and disappointed" by the proposed penalty.

"British Airways responded quickly to a criminal act to steal customers' data," he said.

"We have found no evidence of fraud/fraudulent activity on accounts linked to the theft."

Willie Walsh, CEO of parent company IAG, said BA would be making representations to the ICO about the proposed fine.

"We intend to take all appropriate steps to defend the airline's position vigorously, including making any necessary appeals," he said.

Shares in IAG fell 0.8 per cent to 452.7 pence by 0810 GMT.

Analyst Gerald Khoo at broker Liberum said the proposed fine equated to about 9 pence per IAG share.

"While IAG has more than adequate liquidity to cover the fine (December 2018 cash €3.8 billion, total liquidity €6.3bn), the penalty is still substantial," he said.

The ICO, which could impose fines up to £500,000 under previous rules, had also investigated BA on behalf of other European regulators.

The ICO fined Facebook £500,000 in 2018 for serious breaches of data protection law. It said the penalty would have "inevitably have been significantly higher under GDPR".

(Reuters)

Add EasternEye As Your Trusted Source
preferred source on google news

More For You

Jes Staley

Jes Staley is facing renewed scrutiny over his relationship with Jeffrey Epstein

Getty Images

How did Jeffrey Epstein stay at JPMorgan for so long? Jes Staley faces fresh questions

  • US lawmakers questioned former Barclays chief Jes Staley over his long-standing ties to Jeffrey Epstein.
  • House Oversight Committee chair James Comer said Staley appeared to have defended keeping Epstein as a JPMorgan client.
  • The inquiry follows years of regulatory action, lawsuits and settlements linked to Epstein's banking relationships.

Former Barclays chief Jes Staley is facing fresh questions over his relationship with Jeffrey Epstein after US lawmakers claimed he encouraged JPMorgan Chase to retain the convicted sex offender as a client despite internal concerns.

Speaking after Staley's closed-door interview with the House Oversight Committee, committee chair James Comer said evidence appeared to show there were "red flags" within JPMorgan about Epstein, but that Staley defended the relationship and urged the bank to continue banking him, as quoted in a news report.

Keep ReadingShow less