British Airways runs a website that has reason to watch itself. In 2018 attackers slipped a card-skimming script onto ba.com and its app and lifted the details of hundreds of thousands of transactions before anyone noticed, a breach that ended in one of the largest data-protection fines a UK regulator had issued. An airline burned that way through its own front end invests heavily in knowing what runs on it, which is part of why a careless scraper meets challenges on ba.com fast. Proxies for British Airways are the tool for reading its fares the way a traveler in each market sees them, on a schedule, from connections the site treats as ordinary.
We run a proxy network, and British Airways traffic reaches us from fare trackers, award-search tools and travel-data teams. This page covers what is specific to BA: why the site watches its traffic, how point of sale and Avios vary by market, how it blocks, which proxy type fits and how to size it. The sector background is in travel fare aggregation, the metasearch that carries BA fares is Skyscanner, and the closest sibling with a distribution story of its own is proxies for Lufthansa.
What proxies are best for British Airways?
Rotating residential proxies driven by a real browser, pinned to the country of sale you want, with a static residential (ISP) exit for Executive Club and Avios account work. BA files fares by point of sale and runs strong bot management, so a home connection in the right country is both the accuracy rule and the reputation rule. Keep mobile for the rare run that keeps getting challenged.
A site with a reason to be watchful
Most airline anti-bot writeups treat the defense as generic. On British Airways it helps to know why the defense is as serious as it is. In early September 2018 the airline disclosed that its website and mobile app had been compromised: Magecart attackers placed a payment-card skimming script on the site, running from around 21 August to 5 September 2018, and captured card details from roughly 380,000 transactions, with passengers who booked through the Avios scheme between April and July also at risk (Wikipedia, British Airways data breach). The UK regulator initially proposed a fine of £183 million, later reduced to £20 million (Help Net Security).
The relevance to a data team is indirect but real: British Airways, part of International Airlines Group, has every incentive to monitor exactly what scripts and clients touch its site, and a site instrumented to catch a skimmer is also instrumented to catch a scraper. That is a reason to read ba.com carefully and with clean, ordinary-looking traffic, not a reason to treat it as more forgiving than it is.
2018-08-21
Skimming script goes live on ba.com and the app
Magecart
2018-09-05
Script removed after ~2 weeks
~380,000 transactions hit
2019-07-08
Regulator proposes a £183m fine
later reduced
2020-10-16
Final penalty set at £20m
still a landmark
Point of sale, and Avios, vary by market
BA prices like a European carrier: fares filed by point of sale, quoted in the local market's currency, with some routes cheaper for sale in one country than another. On top of the cash fare, Avios redemption levels and cash-plus-Avios options can differ by the market a booking is made from, so the loyalty price is a market-specific read too. This is the same point-of-sale effect we cover for the metasearch in Skyscanner, and it means reading BA properly is reading it per market, from an exit in each one.
How British Airways blocks you
Ba.com defends its fare and Avios search with strong bot management of the class that guards other major carriers: the client's TLS handshake and JavaScript environment are scored before the IP, the fares load with JavaScript into a near-empty shell, and a client that looks automated is challenged or blocked before the fare engine answers (ScrapingBee, Python flight scraper). The rule is the shared one for defended airline sites: a residential address that starts with a decent trust score, and a real browser whose handshake and behavior match a human.
Which proxy type fits: residential, datacenter, ISP, or mobile
Datacenter proxies are challenged first and misread the point of sale. Use them to test a parser against pages you saved earlier.
Rotating residential proxies are home connections from a pool, one per search, rotated, pinned to the country of sale, and they carry the trust score that clears the defense when paired with a real browser (background in what is a residential proxy).
ISP proxies are static residential addresses for Executive Club and Avios sessions, which must hold on one address.
Mobile proxies are carrier IPs shared across many handsets, a fallback for runs that keep getting challenged.
| British Airways job | Proxy type | Why |
|---|---|---|
| Fare tracking across markets | Rotating residential, country-of-sale pinned | Point of sale plus a clean trust score |
| Avios and cash-plus-Avios reads | Rotating residential per market | Redemption levels vary by market |
| Executive Club account actions | ISP (static residential) | Session and account on one address |
| Runs that keep getting challenged | Mobile | Carrier ranges carry high trust |
| Parser development | Datacenter or free list | Saved pages, nothing at stake |
Free versus paid for British Airways
A free proxy is a shared datacenter address, the profile a watchful airline site challenges first, and it reads the wrong point of sale on top of that. For a single glance at one market, a free proxy may hold, and our free proxy list and proxy checker cost nothing. For a tracker across markets, paid residential behind a real browser is the floor; ours starts at $0.44/GB pay-as-you-go with no KYC.
Setting it up
Drive a real browser behind a residential exit pinned to the country of sale (Playwright, Puppeteer), and let the country site pick its currency. Read each route across the markets you care about, and read Avios levels as their own market-specific data points rather than assuming one redemption price. Rotate one IP per search for public fares and hold a sticky ISP exit for Executive Club work; the split is in rotating vs static residential proxies. Keep the traffic clean and ordinary, because this is a site tuned to notice what is not.
How many IPs, and how fast
Sizing (rotating residential, one refresh cycle):
searches/cycle = routes x dates x markets
= 300 x 60 x 3 = 54,000 searches
per search = a browser render behind bot management
per address = a few searches, then rotate
Refresh near-term dates daily, far dates weekly. The pool spreads it.
Our pricing is per gigabyte with no expiry, so a multi-market tracker pays for the markets it reads.
Staying unblocked on British Airways
- Residential IP in the country of sale, plus a real browser. Accuracy and reputation in one rule.
- Guard the handshake. The TLS fingerprint is scored before the IP.
- Read Avios per market. Redemption levels are not one number.
- Keep it clean and ordinary. A watchful site rewards traffic that looks like a passenger.
- Back off on the first challenge. The checklist is in avoiding IP bans while scraping.
The limits worth knowing
Proxies put a British Airways read on the right point of sale on a trusted connection and spread a tracker so the site sees travelers. They do not beat its bot management alone, they do not change BA's terms of use, and they do not make an unusually watchful site forgiving. Read per market, drive a real browser, and keep the traffic ordinary.
Our free proxy list and proxy checker cover the manual, no-stakes checks for free. For a multi-market fare tracker, rotating residential at $0.44/GB pay-as-you-go behind a real browser, pinned to the country of sale, is what reads British Airways.
Sources
- Wikipedia, British Airways data breach, on the 2018 Magecart skimming attack, the ~380,000 transactions and the Avios-scheme exposure.
- Help Net Security, British Airways is facing £183 million fine for 2018 data breach, and the later reduction to £20 million.
- ScrapingBee, how to build a Python flight scraper, on airline bot management, TLS fingerprinting and the JavaScript shell.