NewsBytes Stage
    Hindi
    More
    In the news
    Narendra Modi
    Amit Shah
    Box Office Collection
    Bharatiya Janata Party (BJP)
    OTT releases
    Hindi
    NewsBytes Stage
    India
    Business
    World
    Politics
    Sports
    Technology
    Entertainment
    Auto
    Lifestyle
    Career
    Visual Stories
    Find Cricket Statistics

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
    Home / News / Technology News / #BritishAirwaysHack: All it took was 22 lines of code
    Next Article
    #BritishAirwaysHack: All it took was 22 lines of code

    #BritishAirwaysHack: All it took was 22 lines of code

    By Shiladitya Ray
    Sep 12, 2018
    07:26 pm

    What's the story

    Following a massive security breach that left the data of 380,000 British Airways customers compromised, cybersecurity firm RiskIQ has now found that it took hackers a mere 22 lines of code to steal the data.

    Meanwhile, UK law enforcement agencies, including the National Crime Agency and the National Cyber Security Centre, are still continuing their investigations into the hack.

    Here are the details.

    Quote

    Personal and financial details of customers were compromised

    "The personal and financial details of customers making bookings on our website and app were compromised. The breach has been resolved and our website is working normally. We've notified the police and relevant authorities," British Airways had said after the breach.

    Hackers?

    RiskIQ thinks a group called Magecraft was responsible

    Drawing on earlier experience, RiskIQ speculated that a hacker group called Magecart was behind the British Airways hack.

    Magecraft was also responsible for the Ticketmaster UK hack earlier this year, which saw the data of 400,000 customers getting compromised.

    Notably, Magecraft's modus operandi involves injecting lines of malicious code into payment forms - an MO which was abundantly clear in the British Airways hack.

    Quote

    The Magecraft hacker group has been active since 2015

    "The Magecart actors have been active since 2015 and have never retreated from their chosen criminal activity. Instead, they have continually refined their tactics and targets to maximize the return on their efforts," said RiskIQ in a statement.

    How?

    How the hackers managed to steal user data

    RiskIQ found that the hackers, using 22 lines of code, modified a Modernizr javascript version 2.6.2 (a library that detects user actions like clicks and taps) on British Airways' website to steal customers' data between August 21 and September 5.

    The modification allowed BA customers' data to be uploaded to the hackers' servers any time someone clicked the 'Submit' button on a payments form.

    BA's woes

    The hack has landed British Airways in trouble

    Several experts have noted that the British Airways should have detected the change to its code on its production server.

    The hack has landed the airlines in a fix, and a law firm called SPG law is currently contemplating suing BA for £500 million - it has already put up a dedicated website where affected users can make a claim.

    Facebook
    Whatsapp
    Twitter
    Linkedin
    Related News
    Latest
    British Airways
    National Crime Records Bureau
    Data Leak

    Latest

    Who is India's most successful Test captain on England soil? Indian Cricket Team
    No duty cuts on British wine in India-UK trade deal United Kingdom
    Sneh Rana records career-best WODI returns against SL; Amanjot shines Indian Women's Cricket Team
    TVS's cheapest e-scooter to be launched soon: What we know TVS Motor Company

    British Airways

    Delhi: NDMC gets SC nod for auctioning Taj Mansingh hotel Delhi Police
    Amul Girl: One of the longest and cheapest ad campaigns India
    Flight services disrupted in Chennai due to heavy rain Chennai
    Google, Microsoft, Amazon are considered most authentic brands in India India

    National Crime Records Bureau

    927 children were raped in Delhi in 2015 Delhi Police
    Himachal polls: Whom should you vote for? Himachal Pradesh
    Bengaluru teen abducted, gang-raped for 10 days; four arrested Karnataka
    Aadhaar-based verification at airports from next year Security

    Data Leak

    Future of Aadhaar: How will 2018 turn out for Aadhaar? India
    Rs. 500 to access Aadhaar details of a billion people India
    Aadhaar at Rs. 500: Know how to protect your data Aadhaar Card
    'Irrespective of laws, result is abuse': Snowden on Aadhaar controversy Aadhaar Card
    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2025