Skip to main content

Hackers could have credit card numbers of 880,000 Orbitz users

Hackers may have gained access to as many as 880,000 credit cards by hacking into the Orbitz website. On Tuesday, March 20, the Expedia-owned travel-booking company shared that it had found evidence of a hacker gaining access to user data. The company doesn’t have evidence that the information was actually taken, but the access means user data could have been stolen.

The hack could include data from travelers that used the platform between January 1 and June 22, 2016. Partner programs using Orbitz have a much wider date range for vulerability, extending to Dec. 22, 2017. Orbitz said that, along with billing information, the hack also could have exposed other personal data including names, emails, phone numbers, billing addresses, and gender. The company’s investigation also suggests that travel itineraries, passport information, and social security numbers were not part of the hack.

The hacker gained access to an older version of the website, according to the company. The current booking platform is not part of that breach, Orbitz said.

Orbitz discovered the hack earlier in March and since has launched an investigation to determine what data could have been affected. After discovering the vulnerability, the company said it hired a forensic investigative firm and also involved law enforcement.

In a statement, Orbitz said, “We deeply regret the incident, and we are committed to doing everything we can to maintain the trust of our customers and partners.”

Willy Leichtera, a cybersecurity expert with Virsec Systems, lauded the company for the promptness of its disclosure, but noted that access to the “older” site is just as troubling.

“First, it’s important to point out the Orbitz announced this breach relatively quickly – within 3 weeks. That may not sound fast, but compared to Equifax (6+ months) and Uber (never, until they got caught), Orbitz did the right thing.”

“What’s more unsettling is the idea that sensitive data for close to a million customers was available in a ‘legacy website.’ That makes it sound like it’s OK to neglect security on older systems while you focus on your latest, coolest apps. If it’s a public-facing website with real data, it’s not legacy – it’s live, and a real liability.”

For those 880,000 users that could have compromised data, the company is offering a year of credit and identity monitoring at no charge. Orbitz says it is notifying users that could have been affected by the breach, but travelers that booked within those dates can also call 855-828-3959 in the U.S. or 512-201-2214 outside the U.S. for additional information.

The breach isn’t the first time hackers have targeted travel platforms. Sabre announced a hack last year on the hotel booking platform. In 2011, a TripAdvisor hack compromised user emails, but the booking platform didn’t collect payment information from users.

Orbitz is owned by Expedia Inc. and offers online booking for flights, accommodations, and rental cars, as well as options like cruises and complete travel packages.

Editors' Recommendations

Hillary K. Grigonis
Hillary never planned on becoming a photographer—and then she was handed a camera at her first writing job and she's been…
The best password managers for 2024
have i been pwned owner uncovers 13 million plaintext passwords leaked from free webhost is a safe password even possible we

If you're thinking about getting a new password manager, we can help narrow down your choices. Here's a list of the best and most secure solutions for taking your logins with you wherever you go, no matter what device you use.
No more retyping passwords every time you switch from your Windows PC to your iPhone or from a Mac to an Android phone. These premium password managers have more than just the basics, making your life easier and keeping your accounts safe at affordable prices.

1Password (Windows, Mac, iOS, Android, Linux, and Chrome OS)

Read more
This Lenovo laptop is normally $2,919 — today it’s $919
The Lenovo ThinkPad T14s Gen 5 opened up on a table.

Lenovo laptop deals aren’t too difficult to come by, but this promotion was so exceptional, it needed its own spotlighting! Right now, Lenovo is knocking $2,000 off the Lenovo ThinkPad T14s. Since it's normally priced at $2,920, it’s hard to say how long this markdown is going to last. If you’ve been sitting on a laptop upgrade for a minute, now might be the time to get some new gear.

Why you should buy the Lenovo ThinkPad T14s laptop
Built for businesses, the ThinkPad has long been the go-to Lenovo laptop for busy professionals. Portability is one of the strong suits here: At 12.50 inches wide, 8.93 inches from front to back, and 0.65 inches tall, the ultraportable T14s is the ideal PC for frequent travelers. It’s lightweight too, weighing but a mere 2.71 pounds.

Read more
Best Dell laptop deals: Cheap laptops starting at $280
The Dell XPS 13 9315 on a table against a window.

Being one of the best laptop brands on the market, it's no surprise that Dell has a huge selection of laptops that you can potentially pick from. Whether you're going for gaming laptops or just normal day-to-day laptops, there's probably a great option for you. In fact, there are even some great budget laptops for those who don't really need anything fancy and just want something basic to get online and access shows or work-related content.
Of course, having so many options can be a bit overwhelming for somebody who isn't familiar with Dell or the laptop market, which is why we scoured the Dell website and other retailers for our favorite picks and listed them below. This list has a lot of crossover with the best Dell XPS deals, student laptop deals and gaming laptop deals, so make sure to check out some of those other great laptop deals as well.

Dell Inspiron 15 -- $280, was $330

Read more