British Airways data breach hackers identified

The attackers behind a data breach that left thousands of British Airways customer details exposed have been identified by security researchers.

RiskIQ has named the Magecart hacking group as the suspected perpetrators behind last week's attack, which saw ore than 300,000 accounts compromised.

The group was able to obtain the names, street and email addresses, credit card numbers, expiry dates and security codes of the airlines customers, which could potentially have allowed them to steal from user accounts.

BA data breach

Magecart first hit the headlines back in June when it was identified as being behind an attack on ticket sales site Ticketmaster.

RiskIQ said that the fact the BA attack bore several trademarks of the group, as it was web-based and targeting credit card data. 

However there was one key difference to the Ticketmaster attack, with Magecart directly targeting the British Airways site, rather than a third-party service as they had done previously, showing that they planned their attack around BA's unique site structure and functionality.

Magecart was also apparently highly aware aware of the way the British Airways mobile app was built, and took advantage of the fact it used much of the same functionality as the website, and could therefore be hijacked in the same way.  

"This attack is a highly targeted approach compared to what we’ve seen in the past with the Magecart skimmer,” said Yonathan Klijnsma, head researcher at RiskIQ. "This skimmer is attuned to how British Airways’ payment page is set up, which tells us that the attackers carefully considered how to target this site in particular."

Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Latest in Security
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
Latest in News
EA Sports F1 25 promotional image featuring drivers Oscar Piastri, Carlos Sainz and Oliver Bearman.
F1 25 has been officially announced, with this year's entry marking a return for Braking Point and a 'significant overhaul' for My Team mode
Garmin clippd integration
Garmin's golf watches just got a big software integration upgrade to help you improve your game
Robert Downey Jr reveals himself as Doctor Doom to a delighted crowd at San Diego Comic-Con 2024
Marvel is currently making a major announcement about Avengers: Doomsday's cast on YouTube, and I think it's going to be a long-winded reveal
Samsung QN90F on yellow background
Samsung announces US prices for its 2025 mini-LED TV lineup, and it’s good and bad news
Nintendo Switch Lite
Forget the Nintendo Switch 2, the original Switch is getting one last hurrah in a surprise Nintendo Direct tomorrow
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
Samsung Galaxy S25 Edge colors seemingly revealed in new video, and there’s another sign of an imminent launch