Skip to main content

Hackers could have credit card numbers of 880,000 Orbitz users

Hackers may have gained access to as many as 880,000 credit cards by hacking into the Orbitz website. On Tuesday, March 20, the Expedia-owned travel-booking company shared that it had found evidence of a hacker gaining access to user data. The company doesn’t have evidence that the information was actually taken, but the access means user data could have been stolen.

The hack could include data from travelers that used the platform between January 1 and June 22, 2016. Partner programs using Orbitz have a much wider date range for vulerability, extending to Dec. 22, 2017. Orbitz said that, along with billing information, the hack also could have exposed other personal data including names, emails, phone numbers, billing addresses, and gender. The company’s investigation also suggests that travel itineraries, passport information, and social security numbers were not part of the hack.

The hacker gained access to an older version of the website, according to the company. The current booking platform is not part of that breach, Orbitz said.

Orbitz discovered the hack earlier in March and since has launched an investigation to determine what data could have been affected. After discovering the vulnerability, the company said it hired a forensic investigative firm and also involved law enforcement.

In a statement, Orbitz said, “We deeply regret the incident, and we are committed to doing everything we can to maintain the trust of our customers and partners.”

Willy Leichtera, a cybersecurity expert with Virsec Systems, lauded the company for the promptness of its disclosure, but noted that access to the “older” site is just as troubling.

“First, it’s important to point out the Orbitz announced this breach relatively quickly – within 3 weeks. That may not sound fast, but compared to Equifax (6+ months) and Uber (never, until they got caught), Orbitz did the right thing.”

“What’s more unsettling is the idea that sensitive data for close to a million customers was available in a ‘legacy website.’ That makes it sound like it’s OK to neglect security on older systems while you focus on your latest, coolest apps. If it’s a public-facing website with real data, it’s not legacy – it’s live, and a real liability.”

For those 880,000 users that could have compromised data, the company is offering a year of credit and identity monitoring at no charge. Orbitz says it is notifying users that could have been affected by the breach, but travelers that booked within those dates can also call 855-828-3959 in the U.S. or 512-201-2214 outside the U.S. for additional information.

The breach isn’t the first time hackers have targeted travel platforms. Sabre announced a hack last year on the hotel booking platform. In 2011, a TripAdvisor hack compromised user emails, but the booking platform didn’t collect payment information from users.

Orbitz is owned by Expedia Inc. and offers online booking for flights, accommodations, and rental cars, as well as options like cruises and complete travel packages.

Editors' Recommendations

Hillary K. Grigonis
Hillary never planned on becoming a photographer—and then she was handed a camera at her first writing job and she's been…
The first 300TB SSD is on the horizon
An SK Hynix SSD over a dark and orange background.

Some of the best SSDs we use are usually 1TB or 2TB, but consumer models go up to 8TB -- which is nothing in the context of a datacenter, and the latest announcement from SK Hynix puts that into perspective. The company revealed that it's currently developing a solid-state drive with a capacity of 300TB, which is a completely unprecedented size. Seeing these enormous SSDs in the flesh might take some time, though.

The company announced the new drive at a press conference in Seoul, South Korea. There are reportedly more interesting products on the way, including various memory solutions, and the focus is entirely on being able to support data centers as the era of AI progresses. According to Tom's Hardware, SK Hynix's market researchers claim that the global volume of data generated on a yearly basis is on an upward trend, and the increase is truly like nothing we've ever seen before. SK Hynix predicts that we'll see a jump up to 660 zettabytes (ZB), up from 15ZB in 2014.

Read more
Best Chromebook deals: Cheap computers starting at $54
HP Elite Dragonfly Chromebook front view showing display and keyboard deck.

If you want to grab yourself a Windows laptop but feel that the prices are pretty high, especially when it comes to the best laptops on the market, you may want to consider going for a Chromebook instead. That's because ChromeOS tends to be a lot more lightweight than Windows, so the specs you have can go a much longer way, and even the best Chromebooks don't cost as much as the best Windows laptops. Even better, you can still get some great Chromebook deals, which is why we went out and collected our favorites below, although if you'd still like to go with a laptop, these laptop deals are a good option too.
HP Chromebook 11A G6 Education Edition -- $46, was $244

Probably one of the cheapest options you're going to find for a Chromebook is this education edition that's made to be as basic as possible to bring the price down. The processor is a very entry-level AMD A4 9120C which is just about enough to get productivity tasks completely, and probably can't handle more complex tasks. The 4 GB of RAM isn't a lot either, but at least with ChromeOS not being as demanding resource-wise, you shouldn't feel it as much as you would on a Windows device. The biggest downside is the 16GB SSD, which means you will almost certainly have to rely on one of these external hard drive deals.

Read more
I would give up my Steam Deck if the ROG Ally 2 had these features
Lies of P running on the Asus ROG Ally.

Last year, I wrote about how I went back to my Steam Deck after using the ROG Ally for several months. Asus' device is a real competitor (read our Asus ROG Ally review to learn why), but there are a handful of aspects of the Steam Deck that make it the right handheld for me. That could change with the ROG Ally 2, however.

Rumor has it that Asus is gearing up to release an updated version of the ROG Ally for 2024. Even if this isn't an entirely new handheld, it's hard to imagine Asus will exit the world of handheld gaming PCs any time soon. And if it makes a few key changes to the next iteration of the ROG Ally, I might finally retire my Steam Deck for good.
No Windows lock screen

Read more