Hundreds of security vulnerabilities still exist on websites of major companies, including Marriott, British Airways and EasyJet, which could lead to data leaks, according to a new study.

It seems that companies are not making much of an effort to protect their systems from data leaks, even after attacks.
The research looked at the security of websites operated by 98 travel companies, including airlines, travel agents, hotel chains, cruise lines and booking sites.
Last year, British Airways and Marriott International were fined millions of pounds as a result of major breaches of their customer data. The cases are still being heard.
The Information Commissioner's Office has recommended a fine of £183 million ($227 million) be imposed on the UK airline and £99 million ($127 million) on the hotel group for breaches of the EU's General Data Protection Regulation (GDPR), as poor security practices led to the exposure of their customers' data.
However, Which?uncovered serious weaknesses in data security that suggest companies have "failed to learn their lessons" from previous breaches that resulted in millions of customer details being leaked.
The study found that Marriott not only had the most vulnerabilities on its websites, but also the most critical issues. Researchers found nearly 500 total security vulnerabilities, with over 100 of them rated as critical. The company appears to have made no progress on its data security, despite having already suffered two major breaches of customer data.

American Airlines was found to have 291 potential vulnerabilities on its websites, with 30 of them being critical. However, it has not yet suffered a breach.
British Airways' websites, on the other hand, have previously been breached, resulting in the data of thousands of its customers being leaked. The investigation found 115 vulnerabilities, including 12 that were deemed critical.
EasyJet, which earlier this year suffered a data breach affecting around nine million customers, had 222 vulnerabilities across nine of its domains revealed by security experts. This included two critical vulnerabilities, one so serious that an attacker could use it to reshape a person’s browsing experience on the website, potentially exposing their private data.
“Travel companies need to step up their game and better protect their customers from cyber threats ,otherwise the ICO should be prepared to step in with tough action, including large fines that will actually be imposed,” said Which?’s Rory Boland. “The government should also allow for a class action regime to deal with mass data breaches, so that companies that fail to take people’s data security seriously are held to account.”
