October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

British Airways’ $229 Million GDPR Fine: Why the Final Penalty Was £20 Million

British Airways was initially threatened with a £183.39 million GDPR penalty, reported as $229 million. The ICO’s final October 2020 fine was £20 million after a breach exposed payment data through altered website JavaScript.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

British Airways was not ultimately fined $229 million. On July 8, 2019, the U.K. Information Commissioner’s Office (ICO) announced a proposed penalty of £183.39 million—reported at the time as about $229 million—for a 2018 breach. After British Airways made representations, the ICO issued a final penalty of £20 million on October 16, 2020. The incident involved compromised Citrix credentials, movement through the airline’s network and altered website JavaScript that sent payment data to an attacker-controlled domain.

What happened to British Airways?

The breach ran from June 22 through September 5, 2018, according to the ICO’s final penalty notice. An attacker used compromised credentials for British Airways’ Citrix remote-access system, gained access to the wider network and eventually modified a JavaScript file used by the airline’s website. The altered script copied payment-card information to the attacker-controlled domain BAways.com.

British Airways contained the relevant vulnerability on September 5 and notified the ICO, payment providers and affected parties beginning September 6. The ICO later concluded that the airline had failed to maintain appropriate technical and organisational measures under GDPR-related security obligations. Read the ICO’s final penalty notice.

The attack was widely described as Magecart-style because it used malicious JavaScript to skim payment details from an online checkout flow. “Magecart” generally describes related payment-page skimming techniques and criminal campaigns, not necessarily one centrally identified organisation.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The key dates and amounts

Date Event
June 22, 2018 The attack period begins, according to the ICO.
September 5, 2018 British Airways blocks the relevant URL paths and contains the incident.
September 6, 2018 The airline notifies the ICO and affected parties; further customer notifications follow on September 7.
July 8, 2019 The ICO announces a notice of intent to fine £183.39 million, reported at the time as approximately $229 million. Contemporaneous coverage.
October 16, 2020 The ICO issues the final penalty: £20 million. Final notice.

The £183.39 million figure was therefore a proposed amount, not money British Airways was finally ordered to pay. The dollar equivalent was a historical conversion used in 2019 reporting; the pound figures are the legally relevant amounts.

How the attack worked

  1. Initial access: compromised Citrix remote-access credentials gave the attacker an entry point.
  2. Network access: the attacker reached other parts of the environment rather than remaining confined to the initial account.
  3. Website tampering: a British Airways JavaScript file was changed.
  4. Data exfiltration: the script copied card information to BAways.com, a domain controlled by the attacker.
  5. Detection and containment: British Airways blocked the relevant paths on September 5, after more than two months of unauthorised access.

In simplified form, the chain was: compromised credentials → internal access → lateral movement → altered payment-page script → card-data exfiltration.

What information was exposed?

The final ICO notice identified approximately 429,612 potentially affected individuals. Earlier public reporting commonly referred to about 500,000 customers. Those figures reflect different stages and methods of estimating the affected population, rather than necessarily describing contradictory events.

Approximate group Information potentially accessed
244,000 people Name, address, card number and CVV
77,000 people Card number and CVV
108,000 people Card number
Employees and administrators Usernames and passwords
Up to 612 Executive Club accounts Usernames and PINs

“Potentially accessed” does not mean every record was necessarily used fraudulently. It describes the data within the affected systems and traffic identified by the regulator.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why did the ICO propose £183.39 million?

The 2019 announcement was the start of an enforcement process. A notice of intent allows the organisation to make representations before the regulator sets a final amount. The ICO said the proposed penalty was about 1.5% of British Airways’ 2017 turnover. At the time, reporting also discussed GDPR’s higher maximum of up to 4% of worldwide annual turnover, subject to the applicable legal provision and statutory calculation.

Current ICO guidance says the higher maximum under the U.K. GDPR and Data Protection Act 2018 is £17.5 million or 4% of worldwide annual turnover, whichever is higher. See the ICO’s maximum-fine guidance.

Why was the final penalty £20 million?

The ICO’s final decision followed British Airways’ representations and further consideration of the facts. Its fining framework requires penalties to be effective, proportionate and dissuasive, while considering factors such as the seriousness of the infringement, its impact on data subjects, the organisation’s size and financial position, cooperation and remedial action. ICO fining guidance explains those principles.

The final notice, rather than the 2019 proposal, is the controlling enforcement outcome. It imposed £20 million under section 155 and Schedule 16 of the Data Protection Act 2018 for infringements relating to the GDPR obligations in force when the breach occurred. The ICO’s 2020–21 annual report confirmed the amount and said British Airways had failed to protect the personal and financial details of more than 400,000 customers and had not detected the attack for more than two months. Annual report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The available record establishes the reduction from £183.39 million to £20 million; it does not establish that British Airways paid the original proposed amount. Nor should the reduction be attributed to one unverified cause. The ICO considered the full statutory factors, including the airline’s response, remediation and financial circumstances.

Was this an EU GDPR fine or a U.K. GDPR fine?

The incident occurred while the EU GDPR applied in the United Kingdom. The final penalty was issued in 2020 under the Data Protection Act 2018 in relation to those GDPR security obligations. It is therefore best described as a U.K. regulatory penalty concerning GDPR requirements, not as a separate post-Brexit enforcement action under today’s terminology.

What British Airways did after discovery

  • Blocked the relevant URL paths and contained the vulnerable route.
  • Notified the ICO, acquiring banks and payment schemes.
  • Notified approximately 496,636 customers on September 6 and another 39,480 on September 7, according to the final notice.
  • Added technical measures, including CrowdStrike Falcon endpoint detection and response.

Those were incident-response and remediation steps. Deploying a later security product is not evidence that the pre-breach controls were adequate or that one tool alone would have prevented the intrusion.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Security lessons for payment-page operators

Protect remote access and privileged accounts

Because compromised Citrix credentials were the described entry point, organisations should require phishing-resistant multifactor authentication where possible, remove dormant accounts, rotate exposed credentials, restrict privileged access and monitor unusual remote sessions. MFA reduces risk but is not a guaranteed prevention measure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Control every script on the payment page

Maintain an inventory of JavaScript, approve changes, monitor for unauthorised modifications and govern third-party code. Content-security policies, subresource integrity where technically suitable, client-side monitoring, hosted payment fields and tokenisation can reduce exposure. PCI DSS and GDPR overlap in security objectives but compliance with one does not automatically prove compliance with the other.

Limit lateral movement

Segment web, payment, identity and administrative environments so that one compromised account cannot freely reach them all. Segmentation adds operational work and can fail when exceptions are poorly controlled, so inventories and continuous review matter.

Detect changes quickly

More than two months of unauthorised access highlights the need for endpoint detection and response, centralised logs, identity monitoring, web-integrity alerts, DNS and egress monitoring, and a tested process for investigating alerts. Tools only help when people review and act on their signals.

Coordinate legal and operational response

Maintain an incident-response plan covering the ICO, payment processors, card schemes, customers, suppliers and contractual deadlines. Document risk assessments and security measures before an incident, not only after one.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the headline should say

The accurate formulation is: British Airways was initially threatened with a £183.39 million GDPR penalty—about $229 million at the time—but the ICO later imposed a final £20 million fine. The case shows why payment-data protection depends on identity security, network controls, application integrity, monitoring and governance working together.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.