British Airways owner IAG has said 185,000 further customers may have had their personal details compromised during a cyber attack.
The group said in a stock exchange announcement that as part of an investigation into a cyber breach which took place earlier this year, it is contacting two groups of customers not previously notified.
This includes the holders of 77,000 payment cards which potentially have the following details compromised:
Card payment information including card number and expiry date
Card verification value
BA customer's personal details without Card Verification Value have also been compromised.
Those impacted were people making reward bookings between April 21 and July 28, 2018, and who used a payment card.
The firm said on Thursday that of the 380,000 payment card details identified, 244,000 were affected.
"While British Airways does not have conclusive evidence that the data was removed from its systems, it is taking a prudent approach in notifying potentially affected customers, advising them to contact their bank or card provider as a precaution," IAG said.
"Since the announcement on September 6, 2018, British Airways can confirm that it has had no verified cases of fraud."
British Airways is facing a multimillion-pound fine as a result of the data breach, which the airline’s chief executive described as a "malicious criminal attack".
Cyber criminals behind the attack obtained enough credit card details to use them, and BA now faces a possible fine of around £500 million over the breach, with the Information Commissioner’s Office (ICO) also investigating the incident.
BA’s data breach took place after the introduction of the new Data Protection Act, which includes the provisions of the new European General Data Protection Regulation (GDPR).
Under the new regulations, the maximum penalty for a company hit with a data breach is a fine of either £17 million or 4% of global turnover, whichever is greater.
In the year ended December 31 2017, BA’s total revenue was £12.2 billion, meaning the company could face a fine of around £500 million if the ICO takes action.