• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechBritish Airways

British Airways Has Yet Another Security Problem, New Report Says

By
Alyssa Newcomb
Down Arrow Button Icon
By
Alyssa Newcomb
Down Arrow Button Icon
August 13, 2019, 9:00 AM ET

One month after being hit with a huge fine over a data breach, British Airways has another security hole that could leave customers’ private information exposed to hackers, according to new research.

The problem is with the unencrypted check-in links that the airline emails to its customers, according to cybersecurity firm Wandera, which found the vulnerability. Those links include passenger details in the URL, such as last names and confirmation numbers, to make it easier for people to automatically log into British Airways’ website.

“We started seeing, within the past two to three months, an increase in the number of unencrypted connections that were destined for British Airways domains,” Michael Covington, vice president at Wandera, tells Fortune. “What we found was the info that was leaking, was typically a person’s name and booking reference number.”

Having those two pieces of information are like “having the keys to the kingdom,” Covington says, since it can allow a hacker using public Wi-Fi to intercept the link request and access other personal information included in a booking. Email addresses, telephone numbers, British Airways loyalty program membership numbers, flight times, and seat numbers were among the pieces of data that could be vulnerable. Passport numbers and payment information were not at risk.

Wandera says it contacted British Airways’ data protection officer twice, but did not receive a response. That role is mandated under GDPR, Europe’s tougher privacy law that went into effect last year, to ensure customer data is protected and that breaches are quickly contained and reported. British Airways says it hasn’t seen those emails.

“We take the security of our customers’ data very seriously. Like other airlines, we are aware of this potential issue and are taking action to ensure our customers remain securely protected,” a British Airways representative tells Fortune. The airline says it has several systems in place that are designed to protect customers’ private information.

British Airways and Wandera say there’s no evidence the flaw has been exploited in the wild. However, Covington says his team estimates that 2.5 million connections were made to the affected British Airways domains over the past six months, showing the potential for mass exploitation.

The report of the vulnerability follows British Airways being slapped with a proposed fine of $221 million by the U.K. Information Commissioner’s Office last month for a breach last year involving the data of 500,000 customers. If the breach had happened before GDPR, the top fine would have merely been $604,000.

In the case of the check-in links, Covington says it’s an easy fix.

“I’m surprised we are seeing this issue now after getting a fine under GDPR,” he says. If British Airways encrypted the links, then he says Wandera, and would-be hackers, wouldn’t be able to pick up on any of the sensitive information in the links.

While it’s nice to not have to log in, Wandera also recommends that customers should be required to log in anytime when their personal information could be accessed and edited.

This story has been updated to include a response from British Airways.

More must-read stories from Fortune:

—What you need to know about 8chan, the controversial site tied to the El Paso shooting

—Verizon’s unlimited plans are getting cheaper. Here’s what you should know

—What CEOs, bankers, and tech execs think about a coming recession

—How an alleged Amazon theft ring got the goods

—Boeing adds a second flight control computer to the 737 Max

Catch up with Data Sheet, Fortune‘s daily digest on the business of tech.

About the Author
By Alyssa Newcomb
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.


Most Popular

placeholder alt text
Success
Marriott’s CEO spoke out about DEI. The next day, he had 40,000 emails from his associates
By Ashley LutzJanuary 1, 2026
2 days ago
placeholder alt text
C-Suite
CEO of $90 billion Waste Management hauled trash and went to 1 a.m. safety briefings—‘It’s not always just dollars and cents’
By Amanda GerutJanuary 3, 2026
8 hours ago
placeholder alt text
Success
Melinda French Gates got her start at Microsoft because an IBM hiring manager told her to turn down its job offer—'It dumbfounded me'
By Emma BurleighDecember 31, 2025
3 days ago
placeholder alt text
Politics
Buddhist monks peace-walking from Texas to DC persist even after being run over on highway outside Houston
By The Associated PressDecember 30, 2025
4 days ago
placeholder alt text
Success
Red Lobster’s 36-year-old CEO led the company after bankruptcy. Now he’s plotting the 'greatest comeback in the history of the restaurant industry'
By Sydney LakeJanuary 2, 2026
1 day ago
placeholder alt text
C-Suite
Exiting CEO left each employee at his family-owned company a $443,000 gift—but they have to stay 5 more years to get all of it
By Nick LichtenbergDecember 30, 2025
4 days ago

Latest in Tech

Bhargava
CommentaryPasswords
You probably use the same password for 30 different websites. It’s time for a passkey. 
By Rishi BhargavaJanuary 3, 2026
2 hours ago
data center
AIData centers
Angry town halls nationwide find a new villain: the data center driving up your electricity bill while fueling job-killing AI
By Marc Levy and The Associated PressJanuary 3, 2026
2 hours ago
tesla
Big TechAutos
Elon Musk promised a ‘major rebound’ for Tesla in 2025. Instead it fell behind its biggest rival from China
By Paul Harloff, Bernard Condon and The Associated PressJanuary 3, 2026
2 hours ago
Sweden
CommentarySweden
Meet Sweden, the unicorn factory chasing America in the AI race
By Oscar TäckströmJanuary 3, 2026
5 hours ago
Man wearing a black suit with a microphone
InvestingMicrostrategy
Michael Saylor’s Strategy flirts again with the danger threshold at which his company is worth less than his Bitcoin
By Jim EdwardsJanuary 2, 2026
24 hours ago
Musk
Travel & LeisureElectric vehicles
Tesla is officially smaller than China’s BYD in EV sales as it reports second-straight year of falling sales
By Nick LichtenbergJanuary 2, 2026
1 day ago