DisclosureLens
HackingTransportation & LogisticsHealthcareTransportationStolen CredentialsCapture Stored DataSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPHIIdentity (basic)Government IDMediumContained

BRITISH AIRWAYS PLC

bd_558f37da1cb2363b · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 4, 2023

Filed

May 10, 2024

To disclose

15 months

Affected

3state residents only

Linked

2 filings

Confidence

66%
Full breach record for BRITISH AIRWAYS PLC2 incidents on file

British Airways Plc notified the New Hampshire AG of a third-party supply chain breach involving vendor Brightline, which serves Aetna (British Airways' behavioral health plan provider). On Jan 31, 2023, Brightline's GoAnywhere MFT instance was compromised via unauthorized credentials, leading to PHI and PII exfiltration. Three NH residents were affected. The incident was contained, and law enforcement was engaged.

Incident timeline

undetected · 4 days
discovery → filing · 15 months / 461 days

Jan 31, 2023

Begins

Feb 4, 2023

Discovered

May 10, 2024

Filed

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Massachusetts State AGMay 10 · first
New Hampshire State AGMay 10 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.