BRITISH AIRWAYS PLC
bd_3db3cca5ab4ee60d · schema v1 · pii pii-v1
Full breach record for BRITISH AIRWAYS PLC →2 incidents on fileBritish Airways PLC notified Washington AG of a cyberattack where malicious code on its website and mobile app redirected customer data (names, billing addresses, payment card numbers, CVVs) to a third-party domain. The incident occurred from Aug 21 to Sep 5, 2018, and was discovered on Sep 5, 2018. Approximately 537,107 customers globally were affected, including 1,588 Washington residents. BA engaged forensic investigators, removed the code, notified customers, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 21, 2018
Begins
Sep 5, 2018
Discovered
Nov 21, 2018
Filed
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Massachusetts State AGbd_5ff5f9a096a206be2018-11-21Verified
- California State AGbd_89733c53fc087c112018-11-21Verified
- Oregon State AGbd_b36bde0aceae97312018-11-21Verified
- New Hampshire State AGbd_8bedfc3683b2f1ca2018-11-26 · +5dVerified
Show 1 more filing ↓Show fewer ↑up to 26d gap
- Montana State AGbd_357c3adfdee25fcb2018-10-26 · +26dCandidate
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Oct 26 (MT), last Nov 26 (NH) — a 31-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.