Skip to main content
  1. Home
  2. Computing
  3. Business
  4. Web
  5. News

Hackers could have credit card numbers of 880,000 Orbitz users

Add as a preferred source on Google

Hackers may have gained access to as many as 880,000 credit cards by hacking into the Orbitz website. On Tuesday, March 20, the Expedia-owned travel-booking company shared that it had found evidence of a hacker gaining access to user data. The company doesn’t have evidence that the information was actually taken, but the access means user data could have been stolen.

The hack could include data from travelers that used the platform between January 1 and June 22, 2016. Partner programs using Orbitz have a much wider date range for vulerability, extending to Dec. 22, 2017. Orbitz said that, along with billing information, the hack also could have exposed other personal data including names, emails, phone numbers, billing addresses, and gender. The company’s investigation also suggests that travel itineraries, passport information, and social security numbers were not part of the hack.

Recommended Videos

The hacker gained access to an older version of the website, according to the company. The current booking platform is not part of that breach, Orbitz said.

Orbitz discovered the hack earlier in March and since has launched an investigation to determine what data could have been affected. After discovering the vulnerability, the company said it hired a forensic investigative firm and also involved law enforcement.

In a statement, Orbitz said, “We deeply regret the incident, and we are committed to doing everything we can to maintain the trust of our customers and partners.”

Willy Leichtera, a cybersecurity expert with Virsec Systems, lauded the company for the promptness of its disclosure, but noted that access to the “older” site is just as troubling.

“First, it’s important to point out the Orbitz announced this breach relatively quickly – within 3 weeks. That may not sound fast, but compared to Equifax (6+ months) and Uber (never, until they got caught), Orbitz did the right thing.”

“What’s more unsettling is the idea that sensitive data for close to a million customers was available in a ‘legacy website.’ That makes it sound like it’s OK to neglect security on older systems while you focus on your latest, coolest apps. If it’s a public-facing website with real data, it’s not legacy – it’s live, and a real liability.”

For those 880,000 users that could have compromised data, the company is offering a year of credit and identity monitoring at no charge. Orbitz says it is notifying users that could have been affected by the breach, but travelers that booked within those dates can also call 855-828-3959 in the U.S. or 512-201-2214 outside the U.S. for additional information.

The breach isn’t the first time hackers have targeted travel platforms. Sabre announced a hack last year on the hotel booking platform. In 2011, a TripAdvisor hack compromised user emails, but the booking platform didn’t collect payment information from users.

Orbitz is owned by Expedia Inc. and offers online booking for flights, accommodations, and rental cars, as well as options like cruises and complete travel packages.

Hillary K. Grigonis
Hillary never planned on becoming a photographer—and then she was handed a camera at her first writing job and she's been…
I upgraded from the M1 MacBook Air to the M5, and here’s what changed for me
The M5 changed more about my workflow than I expected.
Computer, Electronics, Laptop

After about four years with the M1 MacBook Air, I finally pulled the trigger on the M5, and I got there just in time to dodge Apple's recent price hike by eleven days, a story I already told elsewhere, and one that still makes me feel unreasonably smug. Upgrading from the M1 was a multi-generational leap for me, not in the ways mentioned on the spec sheet, but in ways that actually changed how I work every day.

Here’s why that matters in 2026, when the memory crisis has hit the consumer electronics market so badly that even giants like Apple had to cave. MacBook Air M5 launched at $1,099, then climbed to $1,299. 

Read more
Another Googlebook just surfaced online, and this one is from Asus
Asus Googlebook renders reveal a Glow Bar, plenty of ports, and a lightweight chassis
Computer, Electronics, Laptop

Google’s upcoming Googlebook lineup is starting to take shape through leaks. Lenovo has already appeared in several renders, while a recent benchmark leak suggests Dell may bring the XPS name to Google’s new laptop platform. Asus is now the latest manufacturer to surface ahead of launch.

Digital Citizen has published multiple renders of an unannounced Asus Googlebook, showing its lid, keyboard, chassis, and port selection. The laptop could make its official debut at IFA next month. Googlebooks are expected to bring Android apps, ChromeOS technology, deeper phone integration, and Gemini features to a new generation of laptops. Acer, Asus, Dell, HP, and Lenovo are all expected to be part of the first wave.

Read more
I’m done charging things that never leave my desk
Wireless peripherals are better than ever, but I’m starting to value the devices that ask absolutely nothing of me
Computer, Computer Hardware, Computer Keyboard

I have two pairs of wireless earbuds that I rotate during long gaming sessions. When one starts complaining about its battery, I swap in the other pair and put the first one on charge. It’s a mildly ridiculous system, but it works. Apparently, my gaming setup now requires something resembling shift work.

Then my mouse died in the middle of a game.

Read more