Security News > 2021 > July > British Airways data breach lawsuit settled: Airline coughs up potentially millions to make sueball bounce away
British Airways has settled the not-quite-a-class-action* lawsuit against it, potentially paying millions of pounds to make the data breach case in the High Court of England and Wales go away.
"The resolution includes provision for compensation for qualifying claimants who were part of the litigation. The resolution does not include any admission of liability by British Airways Plc," said PGMBM. The lawsuit was based on the 2018 BA data breach, where the credit card details of 380,000 people were stolen thanks to a Magecart infection on its payment processing pages.
The airline had been saving card details in plain text since 2015 and hadn't implemented MFA across the board, as we reported when regulators fined BA for its pisspoor data security practices - including saving a Windows domain admin username and password in plain text.
Law firm Keller Lenkner said on its webpage advertising for British Airways claimants: "In our experience, and looking at similar cases, compensation of around £2,000 per claimant seems likely."
Sky News reported this morning that 16,000 people had applied to be part of the group litigation order, meaning the airline may have paid around £32m - though potentially less - to prevent the case going to trial.
Harris Pogust, chairman of PGMBM, said in the law firm's statement: "The pace at which we have been able to resolve this process with British Airways has been particularly encouraging and demonstrates how seriously the legal system is taking mass data incidents. This is a very positive sign as we look ahead to what will be an even bigger case against EasyJet relating to their 2020 data breach, as well as other similar international actions."
News URL
https://go.theregister.com/feed/www.theregister.com/2021/07/06/british_airways_lawsuit_settled/
Related news
- Fortinet confirms data breach after hacker claims to steal 440GB of files (source)
- 23andMe to pay $30 million in genetics data breach settlement (source)
- 23andMe settles class-action breach lawsuit for $30 million (source)
- AT&T pays $13 million FCC settlement over 2023 data breach (source)
- Dell investigates data breach claims after hacker leaks employee info (source)
- Disney ditching Slack after massive July data breach (source)
- A data leak and a data breach (source)
- U.S. govt agency CMS says data breach impacted 3.1 million people (source)
- Dutch Police: ‘State actor’ likely behind recent data breach (source)
- Comcast and Truist Bank customers caught up in FBCS data breach (source)