BRITISH AIRWAYS PLC
ent_019e5a988d33d975ee72cb4f523b29b1
Disclosures
8
State AG · 6 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
537,107
nationwide · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BRITISH AIRWAYS PLC
- Normalized
- british airways-gb— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 375X9PSJLLOV7F21O626
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- New Hampshire State AGas victim2024-05-10
British Airways Plc notified the New Hampshire AG of a third-party supply chain breach involving vendor Brightline, which serves Aetna (British Airways' behavioral health plan provider). On Jan 31, 2023, Brightline's GoAnywhere MFT instance was compromised via unauthorized credentials, leading to PHI and PII exfiltration. Three NH residents were affected. The incident was contained, and law enforcement was engaged.
- Massachusetts State AGas victim2024-05-10
British Airways Plc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-05-10. 32 Massachusetts residents were affected.
- New Hampshire State AGas victim2018-11-26
British Airways Plc notified New Hampshire AG of a security incident discovered Sept 5, 2018, involving unauthorized access to payment card and personal data. Malicious code redirected customer data between Aug 21 and Sept 5, 2018. Approximately 537,107 customers globally affected, including 228 NH residents. BA engaged forensic investigators, removed malware, notified customers, and offered credit monitoring.
- Washington State AGas victim2018-11-21
British Airways PLC notified Washington AG of a cyberattack where malicious code on its website and mobile app redirected customer data (names, billing addresses, payment card numbers, CVVs) to a third-party domain. The incident occurred from Aug 21 to Sep 5, 2018, and was discovered on Sep 5, 2018. Approximately 537,107 customers globally were affected, including 1,588 Washington residents. BA engaged forensic investigators, removed the code, notified customers, and offered credit monitoring.
- Massachusetts State AGas victim2018-11-21
British Airways PLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-11-21. 2,411 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2018-11-21
British Airways Plc filed a data breach notification with the California Attorney General. The filing lists four dates under 'Date(s) of Breach': April 21, 2018; July 28, 2018; September 5, 2018; and October 21, 2018. No narrative description, affected count, data types, or response actions are provided in the available HTML source.
- Oregon State AGas victim2018-11-21
British Airways Plc reported a data breach to the Oregon Attorney General. The breach was reported on 2018-11-21. The breach occurred during 4/21/2018 - 4/21/2018, 8/21/2018 - 8/21/2018. The breach was discovered on 9/5/2018. 429,000 individuals were affected. Notice was sent on 9/7/201810/25/2018.
- Montana State AGas victim2018-10-26
British Airways Plc notified Montana DOJ of a criminal data theft affecting customers who made bookings between August 21 and September 5, 2018. Compromised data included names, billing addresses, emails, and full payment card details (number, expiry, CVV). The incident was resolved, and the company engaged forensic investigators and the National Crime Agency.