British Airways is facing a multimillion-pound fine as it grapples with the fallout of a massive data breach which the airline's chief executive described as a "malicious criminal attack".
Thousands of BA customers have had to cancel their credit cards after the 15-day data hack compromised 380,000 payments.
Cyber criminals behind the attack obtained enough credit card details to use them, and the firm now faces a possible fine of around £500 million over the breach, with regulators now investigating the incident.
BA's data breach took place after the introduction of the new Data Protection Act, which includes the provisions of the new European General Data Protection Regulation (GDPR).
Under the new regulations, the maximum penalty for a company hit with a data breach is a fine of either £17 million or 4% of global turnover, whichever is greater.
In the year ended December 31 2017, BA's total revenue was £12.2 billion, meaning the company could face a fine of around £500 million if the Information Commissioner's Office (ICO) takes action.
Multiple regulators have been contacted about the data hack, including the National Crime Agency, the National Cyber Security Centre and the ICO.In a statement, an ICO spokesperson said: "British Airways has made us aware of an incident and we are making inquiries."
Alex Cruz, BA’s chairman and chief executive, said the airline was “deeply sorry for the disruption that this criminal activity has caused”.
He said there had been "a very sophisticated, malicious criminal attack on our website".
“We take the protection of our customers’ data very seriously,” he said.
Mr Cruz said BA had “hundreds” of people communicating with customers “making sure that we can help to protect that data”.
Shares in IAG, BA's parent firm, were down more than 3% in morning trade as investors digested the news.
Mr Cruz said that BA is "100% committed" to compensating customers who are financially affected.
"We're extremely sorry. I know that it is causing concern to some of our customers, particularly those customers that made transactions over BA.com and app."
He added: "We know that the information that has been stolen is name, address, email address, credit card information; that would be credit card number, expiration date and the three-letter code in the back of the credit card.
"No itinerary information, no frequent flier data, no passport data has been compromised."
BA said it was investigating the breach, which took place from 11pm on August 21 until 9.45pm on Wednesday, and is co-operating with relevant regulators.
The incident comes after an IT meltdown caused huge disruption for BA passengers at the start of the May half-term holiday.
Some 75,000 passengers were left stranded after a glitch forced the airline to cancel nearly 726 flights over three days.
Following the latest breach, worried customers rushed to social media and helplines after the airline urged anyone who suspected they may have been affected to contact their bank or credit card provider.
There were reports of banks being inundated with calls, leaving account holders in lengthy queues, while some BA customers said they had to have cards cancelled and reissued as a result.
Customer Mat Thomas said he had placed a booking on August 27, but had not been contacted over the breach.
"Atrocious that I had to find out about this via news and twitter," he tweeted."Called bank and had to cancel both mine and my wife's card. Probably won't get it back before we fly (ironically).
"Terrible handling of the situation as I've still not received an email from BA!"
Banks including NatWest and RBS attempted to reassure worried BA customers that they have "significant" levels of security in place, although they advised account holders to be on the lookout for any suspicious activity.
Which? said it was "vital" BA moved quickly to ensure affected customers get clear information and what steps they need to take to protect themselves.