HomeinetBritish Airways: What error caused the recent data leak?

British Airways: What error caused the recent data leak?

The data breach suffered by British Airways, which exposed the payment card details of around 380,000 customers, appears to be the work of the Magecart group, according to a report by RiskIQ.

Following their internal investigation into the hacking incident, British Airways revealed that both their mobile app and website were hacked from August 21 to September 5.

RiskIQ found that the Magecart carried out the attack after BA reported that none of its other services, servers or databases were affected.

This led the research team to conclude that the payment service was the culprit for the data leak, an area that the Magecart team knows quite well.

Fraudsters are known to use web-based card skimmers as a means of stealing credit card payment data.

RiskIQ found that the incriminating element in one of the 50 different JavaScript-based scripts used by the British Airways website to run, namely the Modernizr library, was secretly removed at the end of the default content to avoid detection.

Another obvious piece of evidence that the hackers compromised the JavaScript library file was the difference in the timestamp, with the original, untouched version having a December 2012 stamp, while the version that Magecart changed was dated August 21, the time of the data breach.

The BA application was also affected by the modified Modernizr JavaScript, because it used the same script resources that the website used to allow customers to make payments.

British Airways

Magecart

It has been active since 2015 and has successfully breached data of at least two notable targets.

Researchers also found that all stolen data is sent by the offenders on the baways.com domain to a server located in Romania with the IP address 89.47.162.248, but owned by a Lithuanian VPS (virtual private server) provider called Time4VPS.

Additionally, to make the baways.com domain more trustworthy, the scammers used a paid SSL certificate issued by CA COMODO, instead of using the free LetsEncrypt version which could have left some traces when attached to the British Airways website.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS