Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
British Airways

British Airways Vendor Cyber Rating & Cyber Score

ba.com

As a global airline and the UK’s flag carrier, British Airways has been flying its customers to where they need to be for more than 100 years. The airline connects Britain with the world and the world with Britain, operating one of the most extensive international scheduled airline route networks together with its joint business, codeshare and franchise partners. Together with its affiliates, British Airways operates to around 200 destinations in over 75 countries throughout Europe, North America, South America, Asia, Africa and Australia. In September 2021, British Airways launched its sustainability programme, BA Better World, committing to put sustainability at the heart of everything it does and with a clear roadmap to achieve net


British Airways A.I CyberSecurity Scoring

British Airways
Company Information
Website:http://www.ba.com
Employees number:32,009
Number of followers:1,169,313
NAICS:481
Industry Type:Airlines and Aviation
Homepage:ba.com
British Airways Risk Score (AI oriented)
Between 700 and 749
logo
British AirwaysAirlines and Aviation
Updated:
15/05/2026
733/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
British Airways Global Score (TPRM)
xxxx
logo
British AirwaysAirlines and Aviation
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

British Airways
British AirwaysModerate
Current Score
733Ba (MODERATE)
01000
8 incidents
-15 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
735Before Incident
MAY 2026
748Before Incident
Cyber Attack
15 May 2026British Airways
British Airways: British Airways allegedly breached as hackers claim to have stolen pilot data

British Airways Hit by Cyberattack: Hackers Claim Access to Sensitive Crew and Medical Data

733After Incident
CRITICAL-15
BRI1778826314
British Airways Hit by Cyberattack: Hackers Claim Access to Sensitive Crew and Medical Data The pro-Russian hacktivist group Infrastructure Destruction Squad (also known as Dark Engine) has claimed responsibility for breaching British Airways’ systems, gaining access to highly sensitive data. In a Telegram post, the threat actors stated they infiltrated the airline’s Crew Portal used by pilots and cabin crew to manage schedules, sick leave, and personal information by compromising an individual’s account to reach the admin control panel. The group alleged exposure of sick leave records, including employee names, leave reasons, supervisor approvals, and AI-driven confidence levels evaluating request validity. They also claimed access to Cognino AI 360, an AI data analysis platform, where they reportedly found login credentials, API keys for insurance and financial services, and medical training files containing genetic disease data and health records. Additional compromised data allegedly includes internal network structures, penetration-testing tools, and flight crew schedules. The hackers offered full access to the breached systems including login credentials and sensitive files for $1,000. Screenshots shared on Telegram appear to support their claims, showing the Crew Portal, API servers, and Cognino 360 interfaces. In a follow-up message, the group vowed to escalate attacks, targeting industrial systems, data leaks, ransomware, and malware distribution. British Airways has not publicly responded to the claims, and Cyber Daily has sought further comment from the airline. This incident follows previous breaches at British Airways, including the 2023 MOVEit supply chain attack by the Cl0p ransomware gang and a 2018 Magecart attack that exposed the personal and financial data of 400,000 customers. The Infrastructure Destruction Squad has a history of disrupting critical infrastructure, including water treatment facilities, flood control systems, and industrial control environments across Asia, Latin America, and the EU.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Hacktivism, Financial Gain
IMPACT
Data Compromised: Sick leave records, employee names, leave reasons, supervisor approvals, AI-driven confidence levels, login credentials, API keys, medical training files (genetic disease data, health records), internal network structures, penetration-testing tools, flight crew schedulesSystems Affected: Crew Portal, Cognino AI 360Brand Reputation Impact: HighIdentity Theft Risk: High
DATA BREACH
Employee personal dataMedical dataLogin credentialsAPI keysInternal network structuresSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes
APRIL 2026
747Before Incident
MARCH 2026
746Before Incident
FEBRUARY 2026
744Before Incident
JANUARY 2026
744Before Incident
DECEMBER 2025
741Before Incident
NOVEMBER 2025
741Before Incident
OCTOBER 2025
740Before Incident
SEPTEMBER 2025
738Before Incident
AUGUST 2025
737Before Incident
JULY 2025
735Before Incident
FEBRUARY 2024
714Before Incident
Vulnerability
07 Feb 2024British Airways
MOVEit, MGM Resorts and British Airways: Ransomware Hit $1 Billion in 2023

2023: A Record-Breaking Year for Ransomware as Attacks Surge Past $1 Billion in Extorted Payments

703After Incident
CRITICAL-11
MOVBRIMGM1770602315
2023: A Record-Breaking Year for Ransomware as Attacks Surge Past $1 Billion in Extorted Payments 2023 marked a dramatic resurgence in ransomware activity, with cybercriminals extorting over $1 billion in cryptocurrency payments the highest annual total on record. The year saw a sharp reversal from 2022’s temporary decline, driven by high-profile attacks on critical infrastructure, supply chain vulnerabilities, and the proliferation of Ransomware-as-a-Service (RaaS) models. ### Key Trends and Major Incidents - Supply Chain Attacks Dominate: The MOVEit file transfer software breach, exploited by the Cl0p ransomware group, became one of the most damaging incidents of 2023. The zero-day vulnerability allowed attackers to compromise hundreds of organizations, including British Airways, the BBC, and U.S. government agencies, exposing millions of records. Cl0p’s shift to data exfiltration over encryption proved highly effective, generating over $100 million in ransom payments and accounting for nearly 45% of all ransomware revenue in June and July. - Big Game Hunting Persists: Groups like ALPHV-BlackCat and Cl0p targeted large, deep-pocketed victims, demanding multimillion-dollar ransoms. While MGM Resorts refused to pay after an ALPHV-BlackCat attack, the incident still cost the company over $100 million in damages. - RaaS Lowers the Barrier to Entry: The Phobos and ALPHV-BlackCat strains exemplified the RaaS model, enabling less skilled attackers to launch ransomware campaigns in exchange for a cut of profits. This model fueled a 538% increase in new ransomware variants in 2023, according to Recorded Future. - Rebranding and Affiliate Fluidity: Ransomware groups frequently rebranded or shifted between strains to evade law enforcement and sanctions. Blockchain analysis revealed connections between Trickbot, Royal ransomware, and the 3AM strain, demonstrating how a small number of actors drive much of the ecosystem’s activity. ### Law Enforcement Strikes Back Despite the surge in attacks, 2023 also saw significant law enforcement victories: - FBI’s Hive Takedown: In a six-month infiltration, the FBI disrupted the Hive ransomware group, providing decryption keys to 1,300 victims and preventing an estimated $130 million in ransom payments. Statistical models suggest the operation may have averted over $210 million in total payments by disrupting Hive’s broader operations. - International Collaboration: The BlackCat (ALPHV) disruption and other joint operations highlighted increased coordination between global agencies, cybersecurity firms, and blockchain analysts to track and dismantle ransomware networks. ### Financial Flows and Money Laundering Ransomware proceeds were laundered through a mix of centralized exchanges, mixers, and emerging services like cross-chain bridges, instant exchangers, and gambling platforms. While exchanges remained the most common off-ramping method, sanctioned entities and high-concentration services (e.g., specific mixers) created vulnerabilities for law enforcement to exploit. ### The Broader Impact The $1 billion figure reflects only direct ransom payments not the full economic toll, which includes productivity losses, recovery costs, and reputational damage. The MGM Resorts attack alone demonstrated how even non-payment incidents can inflict nine-figure financial harm. 2023 underscored the adaptability of ransomware actors, who continue to refine tactics, exploit zero-day vulnerabilities, and leverage RaaS to maximize profits. While law enforcement made strides in disruption, the escalating scale and sophistication of attacks signal an enduring and evolving threat.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gainData exfiltration
IMPACT
Financial Loss: > $1 billion (ransom payments alone)Data Compromised: Millions of recordsOperational Impact: Significant (e.g., MGM Resorts incurred over $100 million in damages)Brand Reputation Impact: High (e.g., British Airways, BBC, U.S. government agencies)
DATA BREACH
Personally identifiable informationSensitive corporate dataNumber Of Records Exposed: MillionsSensitivity Of Data: HighData Exfiltration: Yes (Cl0p shifted to data exfiltration over encryption)Data Encryption: Yes (in some cases, e.g., ALPHV-BlackCat)Personally Identifiable Information: Yes
JUNE 2023
742Before Incident
Breach
01 Jun 2023British Airways
British Airways

British Airways Data Breach via Zellis Payroll Service

694After Incident
CRITICAL-48
BRI0112623
British Airways disclosed that the data breach experienced by the payroll service provider Zellis has an effect on them. The BBC and British Airways employees' personal information was exposed as a result of the cyberattack on the payroll service Zellis. According to reports, British Airways was one among the companies damaged by a cyber security attack against MOVEit's target, the UK-based payroll provider Zellis.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Personal Information of Employees
DATA BREACH
Personal Information
AUGUST 2019
693Before Incident
Data Leak
01 Aug 2019British Airways
British Airways

British Airways Data Exposure Incident

645After Incident
CRITICAL-48
BRI0563423
British Airways found a security bug which has the potential to expose passengers’ data, including their flight booking details and personal information. It was an attack that could expose victims’ booking reference numbers, phone numbers, email addresses and more. It was found that bad actors could either view the victim’s personal data, or manipulate their booking information. The exposed information includes email address, telephone numbers, BA membership numbers, first and last name, booking reference, itinerary, flight information like flight number, flight times, and seat number.
INCIDENT DETAILS -
TYPE
Data Exposure
IMPACT
email addresstelephone numbersBA membership numbersfirst and last namebooking referenceitineraryflight numberflight timesseat number
DATA BREACH
email addresstelephone numbersBA membership numbersfirst and last namebooking referenceitineraryflight numberflight timesseat numberemail addresstelephone numbersBA membership numbersfirst and last name
SEPTEMBER 2018
725Before Incident
Data Leak
01 Sep 2018British Airways
British Airways

British Airways Data Breach

663After Incident
CRITICAL-62
BRI45811122
Credit card details of hundreds of thousands of British Airways customers were stolen over a two-week period in the most serious attack on its website and app. It immediately contacted customers when the extent of the breach became clear. Around 380,000 card payments were compromised. Hackers obtained names, street and email addresses, credit card numbers, expiry dates and security codes. The attack came 15 months after the carrier suffered a massive computer system failure at London's Heathrow airport, which stranded 75,000 customers over a holiday weekend. The attackers had not broken the airline's encryption but did not explain exactly how they had obtained the customer information. The attackers had probably targeted a gateway between the airline and a payment processor because no travel details had been stolen. BA advised customers to contact their bank or credit card provider and follow their recommended advice.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial Gain
IMPACT
Credit card numbersExpiry datesSecurity codesNamesStreet and email addressesWebsiteMobile AppPayment Information Risk: High
DATA BREACH
Credit card numbersExpiry datesSecurity codesNamesStreet and email addressesSensitivity Of Data: HighData Encryption: UnbrokenNamesStreet and email addresses
AUGUST 2018
741Before Incident
Cyber Attack
21 Aug 2018British Airways
British Airways Plc

British Airways Data Breach

724After Incident
CRITICAL-17
BRI452080425
The Washington State Office of the Attorney General reported a data breach involving British Airways PLC on November 21, 2018. The breach, which occurred from August 21, 2018 to September 5, 2018, was due to a cyberattack involving malware, potentially exposing the payment card and personal information of approximately 1,588 Washington residents.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Payment card informationPersonal information
DATA BREACH
Payment card informationPersonal information
JUNE 2018
758Before Incident
Cyber Attack
16 Jun 2018British Airways
British Airways

2024 Holiday Season Client-Side Attacks: Polyfill.io Breach and Cisco Magecart Incident

738After Incident
CRITICAL-20
BRI0532305101325
In 2018, British Airways suffered a Magecart (e-skimming) attack where attackers injected malicious JavaScript into its payment checkout page, exploiting a third-party script vulnerability. The breach went undetected for two weeks, during which 380,000 customers' payment card details (including names, addresses, credit card numbers, CVV codes, and expiry dates) were harvested directly from the browser environment. The attack bypassed traditional security measures like WAFs and intrusion detection systems by operating entirely client-side, leveraging encrypted HTTPS traffic to exfiltrate data to attacker-controlled servers. The incident resulted in regulatory fines (£20M by ICO), reputational damage, and a class-action lawsuit from affected customers. The breach highlighted critical gaps in monitoring dynamic client-side code and third-party script dependencies, which remained unaddressed despite robust server-side defenses. The financial and operational fallout extended beyond immediate fraud losses, impacting customer trust during peak travel seasons.
INCIDENT DETAILS -
TYPE
Data BreachSupply Chain AttackE-skimming (Magecart)Client-Side InjectionPayment Card Theft
MOTIVATION
Financial Gain (theft of payment card data during high-transaction holiday season)
IMPACT
Payment card details (e.g., 380,000 records in British Airways breach)Authentication tokensSession cookiesPersonally Identifiable Information (PII) from checkout formsE-commerce platforms (e.g., Cisco merchandise store, Shrwaa.com)Third-party scripts (Polyfill.io, chat widgets, analytics tools)User browsers (client-side execution environment)Disrupted holiday shopping operationsDevelopment freezes limiting patch deploymentIncreased SOC workload during peak seasonConversion Rate Impact: Potential drop due to fake payment forms and compromised checkout flowsCustomer Complaints: Expected increase due to payment fraud and data theftBrand Reputation Impact: High (eroded trust in e-commerce security during critical shopping period)Potential PCI DSS non-compliance finesRegulatory penalties for delayed breach disclosureIdentity Theft Risk: High (stolen payment data used for fraud)Payment Information Risk: Critical (direct theft of card details from checkout pages)
DATA BREACH
Payment card data (card numbers, CVV, expiry dates)Authentication tokensSession cookiesPII from checkout forms (names, addresses, emails)380,000 (British Airways breach)500,000+ websites (Polyfill.io supply chain)Unspecified (Cisco Magecart, Shrwaa.com, Grelos skimmer)Sensitivity Of Data: High (financial and personal data)Data Exfiltration: Yes (to attacker-controlled servers via encrypted HTTPS)Data Encryption: No (data stolen in plaintext from checkout forms)Personally Identifiable Information: Yes (names, addresses, emails, payment details)
APRIL 2018
801Before Incident
Breach
21 Apr 2018British Airways
British Airways Plc

British Airways Data Breach

756After Incident
CRITICAL-45
BRI557072525
The California Office of the Attorney General reported a data breach involving British Airways Plc on November 21, 2018. The breach dates include October 21, 2018, September 5, 2018, April 21, 2018, and July 28, 2018. The breach involved the compromise of personal and financial information of customers, which could have significant consequences for the company and its customers.
INCIDENT DETAILS -
TYPE
Data Breach

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for British Airways ?
?
What was British Airways's A.I Rankiteo Cyber Score in May 2026 ?
?
What was British Airways's A.I Rankiteo Cyber Score in April 2026 ?
?
What was British Airways's A.I Rankiteo Cyber Score in March 2026 ?
?
What was British Airways's A.I Rankiteo Cyber Score in February 2026 ?
?
What was British Airways's A.I Rankiteo Cyber Score in January 2026 ?
?
What was British Airways's A.I Rankiteo Cyber Score in December 2025 ?
?
What was British Airways's A.I Rankiteo Cyber Score in November 2025 ?
?
What was British Airways's A.I Rankiteo Cyber Score in October 2025 ?
?
What was British Airways's A.I Rankiteo Cyber Score in September 2025 ?
?
What was British Airways's A.I Rankiteo Cyber Score in August 2025 ?
?
What was British Airways's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on British Airways's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with British Airways ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view British Airways's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?