# Baways > An educational website that tells the story of the 2018 British Airways cyberattack, where hackers used the domain baways.com to mimic the official British Airways website and steal customer payment data from approximately 300,000-500,000 customers. This domain was originally used maliciously during a sophisticated cyberattack that occurred between August 21 and September 5, 2018. The attack involved injecting malicious JavaScript into British Airways' website that skimmed payment card details and sent them to baways.com - a domain crafted to look like the legitimate ba.com. Today, baways.com has been repurposed as an educational resource created by [cside](https://cside.com) to: - Document the technical details of how the attack unfolded - Explain the timeline from initial compromise to discovery and remediation - Educate about third-party script security vulnerabilities - Demonstrate prevention strategies and modern security tooling - Promote awareness of supply chain attacks and client-side security The site serves as both a historical record and a warning about the ongoing risks of third-party script attacks, while showcasing how cside's monitoring solutions can help prevent similar breaches. ## Story Details - [Complete attack timeline](https://baways.com): Full interactive story covering the 16-day attack period, technical details, aftermath, and lessons learned - [cside security platform](https://cside.com): The company behind this educational site, offering third-party script monitoring and security solutions - [PCI DSS 4.0.1 compliance guide](https://cside.com/blog/pci-dss-4-0-complete-guide-and-steps): Comprehensive guide to meeting PCI DSS 4.0.1 requirements for script monitoring ## Additional Context - [British Airways breach news coverage](https://www.theguardian.com/business/2018/sep/06/british-airways-customer-data-stolen-from-its-website): Guardian article about the original incident - [Technical analysis](https://www.theregister.com/2018/09/11/british_airways_website_scripts/): Register article with technical details about the attack - [ICO penalty document](https://ico.org.uk/media/action-weve-taken/mpns/2618421/ba-penalty-20201016.pdf): Official regulatory response and penalty details