Maximise your Avios, air miles and hotel points

Interesting Sunday Times piece on the British Airways data breach – and possible compensation

Links on Head for Points may pay us an affiliate commission. A list of partners is here.

I have tried to avoid running speculative articles about the British Airways data breach, since few of us can speak with real expert knowledge and even fewer know how the company really operates.

The Sunday Times, however, had a very interesting piece this week which I thought was worth quoting.  They spoke with a consultant called Ben Oguntala who actually worked on fraud prevention at BA’s Waterside head office and who quit after his guidance was ignored.

To quote:

What caused the British Airways data breach?

“Oguntala, 44, founder of the card security company Payments & Co, said he was hired to help improve card payment security. But he discovered the airline had failed the international standard for card payments, called the payment card industry (PCI) data security standard, last year. The failure was not reported in the airline’s annual report.

One internal document presented at a BA meeting in April this year states: “British Airways holds a lot of sensitive payment card data. BA are subjected to the international security standard — PCI data security standard.

“By achieving compliance BA are proving to themselves, their customers and their supervisory bodies that BA are suitably protecting payment card data from malicious attack . . . In December 2017, BA failed to achieve PCI compliance.”

The document warned that an outdated system, ArcSight, was being used to store security data relating to card transactions. It is described in the document as “redundant”, “severely undermined” and “prone to failure”. The document is marked IAG GBS, which is the global business services division of BA’s parent company IAG.

Oguntala said he was shocked at the lax security surrounding credit and debit card payments at BA. “The security was woeful,” he said. “There was card data everywhere and there were no proper controls on where it was going and who was getting access.”

Oguntala, who worked for a team that reported to BA’s information security and compliance manager, considered the entire payment system needed to be radically overhauled — with a new security protocol known as tokenisation. He said he left after his advice was rejected.”

As I said above, this is a quote from an article in The Sunday Times and I have not done any additional verification, but it does have a ring of truth to it.

The full article is here but behind a paywall.

The Times suggests £1,250 per head compensation

Will there be any cash compensation for the data breach?

Without wanting to dampen your hopes, I have very little faith that the £475 million legal suit against British Airways, highlighted in The Times yesterday, will go anywhere.

The (ironically named, for those of us in the loyalty sector) firm of SPG Law is apparently planning a class action lawsuit.  SPG Law is part of a large US law group and so has experience in the class action field, although they are rarely seen in the UK.

Apparently I would be due (£475,000,000 divided by 380,000 people) £1,250 for the “inconvenience, distress and misuse” of my private information. 

More accurately – if we look at the figures for the recent US class action lawsuit brought against British Airways for comparison, where the lawyers took 28% of the settlement as their fee – SPG Law would receive £120 million and I would be due £900.

In reality, we don’t know how the courts will interpret the new GDPR rules on fines for data leakage.  British Airways acted promptly and has not sought to hide anything, it seems, so it would expect a substantial discount for good behaviour.

The original story in The Times is here but, again, is behind a paywall.


how to earn avios from credit cards

How to earn Avios from UK credit cards (June 2021)

As a reminder, there are various ways of earning Avios from UK credit cards.  Many cards also have generous sign-up bonuses!

There are two official British Airways American Express cards:

British Airways American Express card

British Airways American Express

5,000 Avios for signing up, no annual fee and a companion voucher for spending £20,000 Read our full review

BA Premium Plus American Express card BAPP

British Airways American Express Premium Plus

25,000 Avios and the UK’s most valuable credit card perk – the 2-4-1 companion voucher Read our full review

You can also get generous sign-up bonuses by applying for American Express cards which earn Membership Rewards points, such as:

Nectar American Express

American Express Preferred Rewards Gold

Your best beginner’s card – 20,000 points, FREE for a year & two airport lounge passes Read our full review

American Express Platinum card Amex

The Platinum Card from American Express

30,000 points and an unbeatable set of travel benefits – for a fee Read our full review

We also recommend Capital On Tap for limited companies. You earn 1 Avios per £1 which is impressive for a Visa card:

Capital On Tap Business Rewards Visa

The most generous Avios Visa or Mastercard for a limited company Read our full review

Click here to read our detailed summary of all UK credit cards which earn Avios. This includes both personal and small business cards.

(Want to earn more Avios?  Click here to visit our home page for our latest articles on earning and spending your Avios points and click here to see how to earn more Avios this month from offers and promotions.)

Comments (82)

  • pr99 says:

    BA sign off their year end accounts quite quickly however problems with card fraud will turn up within a week. By the time the audit has been signed then it would be fairly easy to evaluate the cost of any problem and include it in the accounts. The accounts are now free from error.

  • Terry S says:

    Myself and my wife booked flights during those ‘dates’ via our BAEC account. We’re BOTH now getting spam calls from an 0113 number……

    • Oli says:

      Does it end in 8891 or 0515 by any chance? Keep getting called by those as well and it only started a few weeks ago!! This might be why…

    • OO says:

      I also booked a flight within this period and on Thursday 13th, I got a spam call from a 0113 number asking if I have been involved in any accident or issue. I work in IT and did a project that involved payment cards and had to ensure PCI compliance. Yes, you have to tokenise the card number and never store the cvv number so was shocked that BA told me my CVV was compromised.

      • Rob says:

        Actually, now you mention it, my wife got one of those calls. It was on her work mobile but I answered it because it was charging in our home office. Her BA account is also compromised.

  • Big dave says:

    and the GDPR 4% of turnover fine is a max. and imposed for repeatedly ignoring and finding out to be non-compliant – if they have jumped through the right hoops (paid off the right people) the fine will be much less

  • Roger1* says:

    About the calls from 0113… , mine was asking me about my recent accident. 🙁

    My question – ‘which one?’ – upset the script and ensured silence while I blocked it as spam.

    I don’t think it was connected with the BA breach.

The UK's biggest frequent flyer website uses cookies, which you can block via your browser settings. Continuing implies your consent to this policy. Our privacy policy is here.