Maximise your Avios, air miles and hotel points

British Airways discloses massive new credit card data breach covering Avios redemption flights

Links on Head for Points may pay us an affiliate commission. A list of partners is here.

The British Airways data breach saga, which first emerged in early September, has taken another painful turn for the airline.

British Airways disclosed on Thursday afternoon that a further 185,000 payment cards had potentially been compromised.

These cards had all been used to pay for Avios redemptions between 21st April and 28th July.

Only online bookings at ba.com were impacted.  Redemptions made via the British Airways app or call centre are safe.

Note that ALL forms of Avios redemption appear to be impacted.  You are included if you used Avios to part-pay for a car rental or hotel booking, according to BA.

It is important to note that this is 185,000 ADDITIONAL payment cards which are affected.  British Airways seems to have massaged the headline figure by stripping out cards which were also caught up in the first data breach.

The full statement is here.

The latest disclosure is broken down as follows:

77,000 payment cards have had their name, billing address, email address, payment number, expiry and CVV potentially compromised

108,000 payment cards have been similarly compromised but without the CVV number

You will receive an email during Friday if you are impacted.  According to BA:

“While we do not have conclusive evidence that the data was removed from British Airways’ systems, we are taking a prudent approach in notifying potentially affected customers, advising them to contact their bank or card provider as a precaution.”

On the upside, further investigation by British Airways into the original data breach last month has found that ‘only’ 244,000 payment cards have been compromised compared with the 380,000 figure originally claimed.

And, of course, Cathay Pacific revealed on Thursday that a whopping 9.4m sets of personal records had been unlawfully accessed.  This includes credit card data.

In some ways, this breach could be worse for BA than the original.  185,000 people represents a high percentage of the active British Airways Executive Club base.  The original breach will have caught up a lot of ‘once a year’ flyers whilst this one will be impacting people like us who make up a disproportionate part of BA revenue.  Anyone who has already sat through the 2017 weekend IT failure and the recent failures of the new FLY check-in system will probably have had enough by now.

You can find the latest BA statement on this latest breach here.

PS.  Having now seen the British Airways email, the heading “Update on Theft of Customer Data” is hugely misleading in my opinion and may lead to the email being deleted unread.


How to earn Avios points from UK credit cards

How to earn Avios from UK credit cards (December 2021)

As a reminder, there are various ways of earning Avios points from UK credit cards.  Many cards also have generous sign-up bonuses!

There are two official British Airways American Express cards with attractive sign-up bonuses:

British Airways BA Amex American Express card

British Airways American Express

5,000 Avios for signing up, no annual fee and an Economy 2-4-1 voucher for spending ….. Read our full review

British Airways BA Premium Plus American Express Amex credit card

British Airways American Express Premium Plus

25,000 Avios and the UK’s most valuable credit card perk – the 2-4-1 companion voucher Read our full review

You can also get generous sign-up bonuses by applying for American Express cards which earn Membership Rewards points, such as:

Nectar American Express

American Express Preferred Rewards Gold

Your best beginner’s card – 20,000 points, FREE for a year & two airport lounge passes Read our full review

American Express Platinum card Amex

The Platinum Card from American Express

30,000 points and an unbeatable set of travel benefits – for a fee Read our full review

Run your own business?

We recommend Capital On Tap for limited companies. You earn 1 Avios per £1 which is impressive for a Visa card, along with a sign-up bonus worth 10,500 Avios:

Capital On Tap Business Rewards Visa

The most generous Avios Visa or Mastercard for a limited company Read our full review

You should also consider the British Airways Accelerating Business credit card. This is open to sole traders as well as limited companies and has a 30,000 Avios sign-up bonus:

British Airways Accelerating Business American Express card

British Airways Accelerating Business American Express

30,000 Avios sign-up bonus – plus annual bonuses of up to 30,000 Avios Read our full review

Click here to read our detailed summary of all UK credit cards which earn Avios. This includes both personal and small business cards.

(Want to earn more Avios?  Click here to visit our home page for our latest articles on earning and spending your Avios points and click here to see how to earn more Avios this month from offers and promotions.)

Comments (251)

This article is closed to new posts. Discussion continues in the HfP Forums.

  • whiskerxx says:

    mmm…
    have received an email from BA advising my card details could have been compromised, including the CVV.
    The card details provided by BA are for a card linked to Curve. It was the Curve card I actually used for payment.
    Curve have already reissued my card following the previous announcement of a breach, even though I didn’t request it, and even though any BA transactions I had made using it were, at that time, outside of the previous window given by BA.

  • Oli says:

    “Was my data stored on ba.com?

    There are a number of ongoing investigations, including a criminal investigation led by the National Crime Agency. It therefore would not be appropriate to comment at this time.”

    Or in other words: “Yes.”

  • geoffthesaint says:

    Atleast we know what sparked the ‘generous’ spend a fiver anywhere to recieve 500 avios offer.

    BA worried people are not using their cards because of the risks…

  • Ted says:

    I received an email from Experian on July 29th, telling me my details (email, cards, address etc) had been found online and were being sold. I was told I should change passwords for pretty much everything and to keep an eye on my accounts.

    Today I receive the Amex, then BA emails telling me my details were breached. I’ll need to look back through everything, as I don’t really keep a close eye on what goes out. I presume I’ll also now need to be vigilant for any finance taken out in my name?

    It’s quite irritating. I have issues with remembering passwords as it is, without having to change them again and now left wondering when some crook might stuff me with a few bills

  • Callum says:

    This is going to happen continuously with multiple companies indefinitely.

    The people overly upset about this should really stop using credit/debit cards anywhere. Perhaps get something like Revolut you can tip up every time you want to use it.

    • Erico1875 says:

      I agree. They can put all the new security in but criminals will break it. Safecrackers

    • Mark says:

      That kind of attitude is part of the problem though. Of course there is no shortage of people out there who will take advantage of any security vulnerabilities. Unfortunately that’s part of the modern world.

      However the onus is very much on companies, particularly major online retailers such as BA, to ensure that their systems are properly designed, implemented, tested and maintained to guard against the risks. The history in this case strongly indicates that’s not happened.

      There’s a reason why fraudsters tend to hit online retailers and not the banks and card issuers directly. The banks realise that security failings could well have a fatal impact on their business. Online retailers and other sites that hold personal data need to start thinking the same way if they aren’t already.

  • Craig says:

    Just back from a ‘quick’ Tenerife and back to the news that I’m also now one of the chosen many! Being pragmatic, the fact that BA and Amex are proactively taking responsibility for the howler and that the password I use on those sites isn’t the same as any other leave me mostly unconcerned. I check my accounts most days, if I see something untoward then I’ll make the call and dare them to say it’s my fault. Don’t get me wrong, I fully understand peoples concerns and I’m not being totally blasé, just take basic precautions and ‘trust’ the large corporations to sort out their own FU’s.

  • Seat54 says:

    I too am on the sinking ship.

    Is it only the card used for the booking or is it any cards on the account, it says if you made a booking it does not say specifically whether it’s the card used or the cards on the account..

    Also from the BA site I wonder why this only says AMEX……what about other cards………

    Will I be liable for any fraudulent activity?

    American Express Cardmembers are not liable for any fraudulent charges on their credit cards.

    • Hugh says:

      I suspect everybody else, once they spoke/speak to their Visa/Mastercard companies, have had their cards changed!

      AMEX have from day 1 of this current debacle, gone down the route of saying we’re monitoring your account, no need for new card numbers

  • hingeless says:

    It looks like you need a UK phone number to sign up for the experian site, i don’t have one . . .

    hacked off !

    • Alex W says:

      Make one up? I pity if anyone ever has the misfortune of actually owning the phone number 07890123456.

      • hingeless says:

        BA seems to be assuming all its customers live in the UK. You would think an airline would know better !!

      • Peter K says:

        Mrs K had someone else use her mobile number repeatedly and it had been a right royal nuisance for her with unsolicited sales calls etc though her number is on the TPS. Casey Walker, here’s looking daggers at you!!

      • RussellH says:

        If a site insists on a mobile number, my partner and I usually use 07000 000000. There is no usable mobile signal in the house, and as neither of us work anymore we are unlikely to have a phone turned on when away from home, unless we are expecting someone to phone us.

        I was asked recently by an intelligent CS person if that really was my mobile number. I explained why I used it. When I explained she laughed, said that she understood the reasoning and that she would leave the number as it stood.

        • Lady London says:

          Errr @RussellH they probably asked you about that number, because it’s already in use with me for quite some time.

    • Roger1* says:

      hingeless: you could consider using 0333 8888 8888 – that’s 3x 3 and 8x 8.

      The call is answered with a request to contact you by e-mail.

      Also works with 7x 8, I believe: 0333 888 8888.

    • RussellH says:

      Try any number starting 01632 – the original, long superseded code for Newcastle/Tyne. These days it is the OFCOM approved dialing code for use in signage in films and TV programmes.

This article is closed to new posts. Discussion continues in the HfP Forums.