Skip to main content

Hackers could have credit card numbers of 880,000 Orbitz users

Hackers may have gained access to as many as 880,000 credit cards by hacking into the Orbitz website. On Tuesday, March 20, the Expedia-owned travel-booking company shared that it had found evidence of a hacker gaining access to user data. The company doesn’t have evidence that the information was actually taken, but the access means user data could have been stolen.

The hack could include data from travelers that used the platform between January 1 and June 22, 2016. Partner programs using Orbitz have a much wider date range for vulerability, extending to Dec. 22, 2017. Orbitz said that, along with billing information, the hack also could have exposed other personal data including names, emails, phone numbers, billing addresses, and gender. The company’s investigation also suggests that travel itineraries, passport information, and social security numbers were not part of the hack.

The hacker gained access to an older version of the website, according to the company. The current booking platform is not part of that breach, Orbitz said.

Orbitz discovered the hack earlier in March and since has launched an investigation to determine what data could have been affected. After discovering the vulnerability, the company said it hired a forensic investigative firm and also involved law enforcement.

In a statement, Orbitz said, “We deeply regret the incident, and we are committed to doing everything we can to maintain the trust of our customers and partners.”

Willy Leichtera, a cybersecurity expert with Virsec Systems, lauded the company for the promptness of its disclosure, but noted that access to the “older” site is just as troubling.

“First, it’s important to point out the Orbitz announced this breach relatively quickly – within 3 weeks. That may not sound fast, but compared to Equifax (6+ months) and Uber (never, until they got caught), Orbitz did the right thing.”

“What’s more unsettling is the idea that sensitive data for close to a million customers was available in a ‘legacy website.’ That makes it sound like it’s OK to neglect security on older systems while you focus on your latest, coolest apps. If it’s a public-facing website with real data, it’s not legacy – it’s live, and a real liability.”

For those 880,000 users that could have compromised data, the company is offering a year of credit and identity monitoring at no charge. Orbitz says it is notifying users that could have been affected by the breach, but travelers that booked within those dates can also call 855-828-3959 in the U.S. or 512-201-2214 outside the U.S. for additional information.

The breach isn’t the first time hackers have targeted travel platforms. Sabre announced a hack last year on the hotel booking platform. In 2011, a TripAdvisor hack compromised user emails, but the booking platform didn’t collect payment information from users.

Orbitz is owned by Expedia Inc. and offers online booking for flights, accommodations, and rental cars, as well as options like cruises and complete travel packages.

Editors' Recommendations

Hillary K. Grigonis
Hillary never planned on becoming a photographer—and then she was handed a camera at her first writing job and she's been…
Nvidia could flip the script on the RTX 5090
The Hyte Y40 PC case sitting on a table.

We already know Nvidia is working on its RTX 50-series graphics cards, code-named Blackwell, but the rollout may not go as expected.

According to well-known hardware leaker kopite7kimi, Nvidia plans to launch the RTX 5080 before it launches the RTX 5090. That may not sound like a big deal, but it's a change of pace compared to what we saw in the last generation.

Read more
Best laptop deals: Save on the Dell XPS 14, MacBook Pro 16 and more
The Dell XPS 14 on a white table with the screen open.

While having a desktop computer can be pretty great, laptops offer you a lot of portability, which is especially important if you need something to take with you to work or school. Luckily, there are a lot of choices to pick from, and while the best laptops tend to be quite expensive, there are some pretty great deals that will get you pretty close. There are also a lot of the best laptop brands offering solid budget and mid-range laptops, so even if you're buying on a budget, there's likely a good option for you.

HP Chromebook 14a -- $300, was $370

Read more
The new iPad Pro would be perfect, if only it were a Mac
A person gaming on the M4 iPad Pro and playing Diablo Immortal.

It’s no secret that I’ve been cheering on Apple’s gaming advances over the last year or so. Long-suffering Mac gamers have gone from being the forgotten also-rans of Apple’s ecosystem to feeling on top of the world, all in a very short period of time. But there’s one vital piece missing from the puzzle, and Apple’s new M4 iPad Pros have made it incredibly obvious.

I’ll admit, Mac gamers have been treated well in recent times. Not only have we had phenomenal hardware advancements in the form of the M3 Max chip -- which is a genuine gaming chip so cool and quiet that you’d be fooled into thinking it’s not -- but there’s also been a slate of top-tier games arriving on Apple’s platform, including my beloved Baldur’s Gate 3. It’s a good time to be a Mac gamer.

Read more