• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

MacKenzie Scott alone accounted for one-third of America's $19.2 billion in megagifts last year

2

Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic

3

Ikea’s billionaire founder was so frugal that he bought clothes from flea markets and took free salt and pepper from restaurants

1

MacKenzie Scott alone accounted for one-third of America's $19.2 billion in megagifts last year

2

Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic

3

Ikea’s billionaire founder was so frugal that he bought clothes from flea markets and took free salt and pepper from restaurants
TechBritish Airways

British Airways Has Yet Another Security Problem, New Report Says

By
Alyssa Newcomb
Alyssa Newcomb
Down Arrow Button Icon
By
Alyssa Newcomb
Alyssa Newcomb
Down Arrow Button Icon
August 13, 2019, 9:00 AM ET
Add Fortune on Google for similar content.

One month after being hit with a huge fine over a data breach, British Airways has another security hole that could leave customers’ private information exposed to hackers, according to new research.

The problem is with the unencrypted check-in links that the airline emails to its customers, according to cybersecurity firm Wandera, which found the vulnerability. Those links include passenger details in the URL, such as last names and confirmation numbers, to make it easier for people to automatically log into British Airways’ website.

“We started seeing, within the past two to three months, an increase in the number of unencrypted connections that were destined for British Airways domains,” Michael Covington, vice president at Wandera, tells Fortune. “What we found was the info that was leaking, was typically a person’s name and booking reference number.”

Having those two pieces of information are like “having the keys to the kingdom,” Covington says, since it can allow a hacker using public Wi-Fi to intercept the link request and access other personal information included in a booking. Email addresses, telephone numbers, British Airways loyalty program membership numbers, flight times, and seat numbers were among the pieces of data that could be vulnerable. Passport numbers and payment information were not at risk.

Wandera says it contacted British Airways’ data protection officer twice, but did not receive a response. That role is mandated under GDPR, Europe’s tougher privacy law that went into effect last year, to ensure customer data is protected and that breaches are quickly contained and reported. British Airways says it hasn’t seen those emails.

“We take the security of our customers’ data very seriously. Like other airlines, we are aware of this potential issue and are taking action to ensure our customers remain securely protected,” a British Airways representative tells Fortune. The airline says it has several systems in place that are designed to protect customers’ private information.

British Airways and Wandera say there’s no evidence the flaw has been exploited in the wild. However, Covington says his team estimates that 2.5 million connections were made to the affected British Airways domains over the past six months, showing the potential for mass exploitation.

The report of the vulnerability follows British Airways being slapped with a proposed fine of $221 million by the U.K. Information Commissioner’s Office last month for a breach last year involving the data of 500,000 customers. If the breach had happened before GDPR, the top fine would have merely been $604,000.

In the case of the check-in links, Covington says it’s an easy fix.

“I’m surprised we are seeing this issue now after getting a fine under GDPR,” he says. If British Airways encrypted the links, then he says Wandera, and would-be hackers, wouldn’t be able to pick up on any of the sensitive information in the links.

While it’s nice to not have to log in, Wandera also recommends that customers should be required to log in anytime when their personal information could be accessed and edited.

This story has been updated to include a response from British Airways.

More must-read stories from Fortune:

—What you need to know about 8chan, the controversial site tied to the El Paso shooting

—Verizon’s unlimited plans are getting cheaper. Here’s what you should know

—What CEOs, bankers, and tech execs think about a coming recession

—How an alleged Amazon theft ring got the goods

—Boeing adds a second flight control computer to the 737 Max

Catch up with Data Sheet, Fortune‘s daily digest on the business of tech.

About the Author
By Alyssa Newcomb
See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

gas
LawAntitrust
Gas station owners have found a use case for AI, lawsuit says: colluding to fix prices
By R.J. Rico and The Associated PressJune 25, 2026
9 hours ago
g
AIunemployment
One of the Democratic Party’s brightest stars is co-founding a group to help with the coming AI jobs earthquake
By Josh Boak and The Associated PressJune 25, 2026
9 hours ago
apes
HealthAnimals
Scientists tickled monkeys to find if they have the same giggles as humans — and they do
By Adithi Ramakrishnan and The Associated PressJune 25, 2026
9 hours ago
GTA 6 release date is finally here—but the $80 price tag and missing disc have gamers furious
Arts & EntertainmentGaming
GTA 6 release date is finally here—but the $80 price tag and missing disc have gamers furious
By Whizy Kim and Tech BrewJune 25, 2026
12 hours ago
stock
InvestingMarkets
How one chip stock reversed the global tech selloff, exposed AI’s ‘memory tax’ and made the case for an entire valuation regime change
By Nick LichtenbergJune 25, 2026
15 hours ago
Larry Ellison quietly gave $45 million to a pro-Trump group—then Oracle landed a starring role in a $500 billion AI buildout
PoliticsLarry Ellison
Larry Ellison quietly gave $45 million to a pro-Trump group—then Oracle landed a starring role in a $500 billion AI buildout
By Sydney LakeJune 25, 2026
15 hours ago

Most Popular

MacKenzie Scott alone accounted for one-third of America's $19.2 billion in megagifts last year
Success
MacKenzie Scott alone accounted for one-third of America's $19.2 billion in megagifts last year
By Sydney LakeJune 25, 2026
24 hours ago
Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic
Success
Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic
By Orianna Rosa RoyleJune 24, 2026
2 days ago
Ikea’s billionaire founder was so frugal that he bought clothes from flea markets and took free salt and pepper from restaurants
Success
Ikea’s billionaire founder was so frugal that he bought clothes from flea markets and took free salt and pepper from restaurants
By Orianna Rosa RoyleJune 25, 2026
24 hours ago
Current price of silver as of Thursday, June 25, 2026
Personal Finance
Current price of silver as of Thursday, June 25, 2026
By Joseph HostetlerJune 25, 2026
18 hours ago
Current price of oil as of June 25, 2026
Personal Finance
Current price of oil as of June 25, 2026
By Joseph HostetlerJune 25, 2026
18 hours ago
Trump turns on Big Oil donors who spent nearly $100 million to get him elected—now he wants the DOJ to investigate them for price gouging
Economy
Trump turns on Big Oil donors who spent nearly $100 million to get him elected—now he wants the DOJ to investigate them for price gouging
By Tristan BoveJune 25, 2026
10 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.