BA Data Breach Could Have Been Prevented by Web Application Firewalls
Web application firewalling would have protected against unauthorized data exposure if configured correctly
7 September 2018 – Following the announcement by British Airways that the details of 380,000 payment card details and other personal data had been stolen from its website, Link11 stated that the breach could have been prevented with the use of a correctly-configured web application firewalling (WAF) to protect the British Airways website.
British Airways confirmed that enough information was stolen from its website to allow criminals to use credit card information for illicit purposes. The data stolen includes customers’ names, addresses, email addresses and credit card information including the card number, expiration date and the three-letter security code on the back of the card.
According to Link11’s regional director for UK & Ireland for Link11, Aatish Pattni: "The attack on BA's website happened over a 15-day period so it's likely the criminals were stealthily exploring BA's site and systems for vulnerabilities that they could exploit. It is likely the theft could have been prevented with the use of web application firewalling, which inspects and filters traffic on websites. This means it can stop data theft, and prevent commonly-used website attacks such as SQL injection and cross-site scripting.
“It seems that BA may not have had this protection in place, or it wasn't configured correctly – but the result is the largest data breach in the UK since GDPR came into effect, which could have further ramifications for BA. With solutions such as Link11’s, companies can have always-on protection to stop these types of breaches happening."
Link11's cloud-based Web Application Firewall (WAF) service is an add-on to the company’s cloud-based Web DDoS Protection. It protects website applications and APIs against all common web application threats, and against unauthorized data exposure, fraud or theft. Mission critical applications that rely on storing user data get complete protection against all common web application threats and attacks with a single solution.
“Even well-accepted security standards such as PCI DSS recommend that organizations deploy a Web Application Firewall. Every enterprise is a potential target for data theft and needs to protect their mission critical web applications, services and APIs,” added Pattni.
Stay updated on current DDoS reports, warnings, and news about IT security, cybercrime and DDoS protection.
Follow Link11 on Twitter
That was a great first day at IT-SA in Nuremberg! Today, we talked to Lasse Berger from Bayerischer Rundfunk about…
1 Retweets 2Read More
We are having a great time at it-sa - The IT Security Expo and Congress with Link11 COO Marc Wilczek on stage, tal…
2 Retweets 1Read More
Cybersecurity incidents are expected to rise by an alarming 70% by 2024. As the world is going digital, criminal ac…
0 Retweets 0Read More
Meet the team! Visit our booth (10.0-413) at it-sa 2019 from October 8-10 in Nuremberg and talk to our experts!…
1 Retweets 3Read More
Meet our team at it-sa 2019 from October 8-10 in Nuremberg in hall 10.0, booth 413 and talk to our experts!…
0 Retweets 1Read More
Cyber-security to be the number one threat to the global economy in the next decade, survey shows.…
0 Retweets 2Read More
Almost all cyber attacks last year could have been prevented, research shows. The over 2 million cyber incidents re…
1 Retweets 0Read More