A malicious code-injection campaign targeted British Airways' digital booking architecture. The script intercepted and exfiltrated payment card details, CVV codes, and travel booking logs from global travelers, including thousands of Australian customers.