The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →British Airways was not ultimately fined $229 million. On July 8, 2019, the U.K. Information Commissioner’s Office (ICO) announced a proposed penalty of £183.39 million—reported at the time as about $229 million—for a 2018 breach. After British Airways made representations, the ICO issued a final penalty of £20 million on October 16, 2020. The incident involved compromised Citrix credentials, movement through the airline’s network and altered website JavaScript that sent payment data to an attacker-controlled domain.
What happened to British Airways?
The breach ran from June 22 through September 5, 2018, according to the ICO’s final penalty notice. An attacker used compromised credentials for British Airways’ Citrix remote-access system, gained access to the wider network and eventually modified a JavaScript file used by the airline’s website. The altered script copied payment-card information to the attacker-controlled domain BAways.com.
British Airways contained the relevant vulnerability on September 5 and notified the ICO, payment providers and affected parties beginning September 6. The ICO later concluded that the airline had failed to maintain appropriate technical and organisational measures under GDPR-related security obligations. Read the ICO’s final penalty notice.
The attack was widely described as Magecart-style because it used malicious JavaScript to skim payment details from an online checkout flow. “Magecart” generally describes related payment-page skimming techniques and criminal campaigns, not necessarily one centrally identified organisation.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
The key dates and amounts
| Date | Event |
|---|---|
| June 22, 2018 | The attack period begins, according to the ICO. |
| September 5, 2018 | British Airways blocks the relevant URL paths and contains the incident. |
| September 6, 2018 | The airline notifies the ICO and affected parties; further customer notifications follow on September 7. |
| July 8, 2019 | The ICO announces a notice of intent to fine £183.39 million, reported at the time as approximately $229 million. Contemporaneous coverage. |
| October 16, 2020 | The ICO issues the final penalty: £20 million. Final notice. |
The £183.39 million figure was therefore a proposed amount, not money British Airways was finally ordered to pay. The dollar equivalent was a historical conversion used in 2019 reporting; the pound figures are the legally relevant amounts.
How the attack worked
- Initial access: compromised Citrix remote-access credentials gave the attacker an entry point.
- Network access: the attacker reached other parts of the environment rather than remaining confined to the initial account.
- Website tampering: a British Airways JavaScript file was changed.
- Data exfiltration: the script copied card information to BAways.com, a domain controlled by the attacker.
- Detection and containment: British Airways blocked the relevant paths on September 5, after more than two months of unauthorised access.
In simplified form, the chain was: compromised credentials → internal access → lateral movement → altered payment-page script → card-data exfiltration.
What information was exposed?
The final ICO notice identified approximately 429,612 potentially affected individuals. Earlier public reporting commonly referred to about 500,000 customers. Those figures reflect different stages and methods of estimating the affected population, rather than necessarily describing contradictory events.
Rank #2
| Approximate group | Information potentially accessed |
|---|---|
| 244,000 people | Name, address, card number and CVV |
| 77,000 people | Card number and CVV |
| 108,000 people | Card number |
| Employees and administrators | Usernames and passwords |
| Up to 612 Executive Club accounts | Usernames and PINs |
“Potentially accessed” does not mean every record was necessarily used fraudulently. It describes the data within the affected systems and traffic identified by the regulator.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Why did the ICO propose £183.39 million?
The 2019 announcement was the start of an enforcement process. A notice of intent allows the organisation to make representations before the regulator sets a final amount. The ICO said the proposed penalty was about 1.5% of British Airways’ 2017 turnover. At the time, reporting also discussed GDPR’s higher maximum of up to 4% of worldwide annual turnover, subject to the applicable legal provision and statutory calculation.
Current ICO guidance says the higher maximum under the U.K. GDPR and Data Protection Act 2018 is £17.5 million or 4% of worldwide annual turnover, whichever is higher. See the ICO’s maximum-fine guidance.
Rank #3
Why was the final penalty £20 million?
The ICO’s final decision followed British Airways’ representations and further consideration of the facts. Its fining framework requires penalties to be effective, proportionate and dissuasive, while considering factors such as the seriousness of the infringement, its impact on data subjects, the organisation’s size and financial position, cooperation and remedial action. ICO fining guidance explains those principles.
The final notice, rather than the 2019 proposal, is the controlling enforcement outcome. It imposed £20 million under section 155 and Schedule 16 of the Data Protection Act 2018 for infringements relating to the GDPR obligations in force when the breach occurred. The ICO’s 2020–21 annual report confirmed the amount and said British Airways had failed to protect the personal and financial details of more than 400,000 customers and had not detected the attack for more than two months. Annual report.
Recommended Free Tools
The available record establishes the reduction from £183.39 million to £20 million; it does not establish that British Airways paid the original proposed amount. Nor should the reduction be attributed to one unverified cause. The ICO considered the full statutory factors, including the airline’s response, remediation and financial circumstances.
Rank #4
Was this an EU GDPR fine or a U.K. GDPR fine?
The incident occurred while the EU GDPR applied in the United Kingdom. The final penalty was issued in 2020 under the Data Protection Act 2018 in relation to those GDPR security obligations. It is therefore best described as a U.K. regulatory penalty concerning GDPR requirements, not as a separate post-Brexit enforcement action under today’s terminology.
What British Airways did after discovery
- Blocked the relevant URL paths and contained the vulnerable route.
- Notified the ICO, acquiring banks and payment schemes.
- Notified approximately 496,636 customers on September 6 and another 39,480 on September 7, according to the final notice.
- Added technical measures, including CrowdStrike Falcon endpoint detection and response.
Those were incident-response and remediation steps. Deploying a later security product is not evidence that the pre-breach controls were adequate or that one tool alone would have prevented the intrusion.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Security lessons for payment-page operators
Protect remote access and privileged accounts
Because compromised Citrix credentials were the described entry point, organisations should require phishing-resistant multifactor authentication where possible, remove dormant accounts, rotate exposed credentials, restrict privileged access and monitor unusual remote sessions. MFA reduces risk but is not a guaranteed prevention measure.
Best Value
Control every script on the payment page
Maintain an inventory of JavaScript, approve changes, monitor for unauthorised modifications and govern third-party code. Content-security policies, subresource integrity where technically suitable, client-side monitoring, hosted payment fields and tokenisation can reduce exposure. PCI DSS and GDPR overlap in security objectives but compliance with one does not automatically prove compliance with the other.
Limit lateral movement
Segment web, payment, identity and administrative environments so that one compromised account cannot freely reach them all. Segmentation adds operational work and can fail when exceptions are poorly controlled, so inventories and continuous review matter.
Detect changes quickly
More than two months of unauthorised access highlights the need for endpoint detection and response, centralised logs, identity monitoring, web-integrity alerts, DNS and egress monitoring, and a tested process for investigating alerts. Tools only help when people review and act on their signals.
Coordinate legal and operational response
Maintain an incident-response plan covering the ICO, payment processors, card schemes, customers, suppliers and contractual deadlines. Document risk assessments and security measures before an incident, not only after one.
What the headline should say
The accurate formulation is: British Airways was initially threatened with a £183.39 million GDPR penalty—about $229 million at the time—but the ICO later imposed a final £20 million fine. The case shows why payment-data protection depends on identity security, network controls, application integrity, monitoring and governance working together.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




