Skip to main content

Hackers could have credit card numbers of 880,000 Orbitz users

Hackers may have gained access to as many as 880,000 credit cards by hacking into the Orbitz website. On Tuesday, March 20, the Expedia-owned travel-booking company shared that it had found evidence of a hacker gaining access to user data. The company doesn’t have evidence that the information was actually taken, but the access means user data could have been stolen.

The hack could include data from travelers that used the platform between January 1 and June 22, 2016. Partner programs using Orbitz have a much wider date range for vulerability, extending to Dec. 22, 2017. Orbitz said that, along with billing information, the hack also could have exposed other personal data including names, emails, phone numbers, billing addresses, and gender. The company’s investigation also suggests that travel itineraries, passport information, and social security numbers were not part of the hack.

The hacker gained access to an older version of the website, according to the company. The current booking platform is not part of that breach, Orbitz said.

Orbitz discovered the hack earlier in March and since has launched an investigation to determine what data could have been affected. After discovering the vulnerability, the company said it hired a forensic investigative firm and also involved law enforcement.

In a statement, Orbitz said, “We deeply regret the incident, and we are committed to doing everything we can to maintain the trust of our customers and partners.”

Willy Leichtera, a cybersecurity expert with Virsec Systems, lauded the company for the promptness of its disclosure, but noted that access to the “older” site is just as troubling.

“First, it’s important to point out the Orbitz announced this breach relatively quickly – within 3 weeks. That may not sound fast, but compared to Equifax (6+ months) and Uber (never, until they got caught), Orbitz did the right thing.”

“What’s more unsettling is the idea that sensitive data for close to a million customers was available in a ‘legacy website.’ That makes it sound like it’s OK to neglect security on older systems while you focus on your latest, coolest apps. If it’s a public-facing website with real data, it’s not legacy – it’s live, and a real liability.”

For those 880,000 users that could have compromised data, the company is offering a year of credit and identity monitoring at no charge. Orbitz says it is notifying users that could have been affected by the breach, but travelers that booked within those dates can also call 855-828-3959 in the U.S. or 512-201-2214 outside the U.S. for additional information.

The breach isn’t the first time hackers have targeted travel platforms. Sabre announced a hack last year on the hotel booking platform. In 2011, a TripAdvisor hack compromised user emails, but the booking platform didn’t collect payment information from users.

Orbitz is owned by Expedia Inc. and offers online booking for flights, accommodations, and rental cars, as well as options like cruises and complete travel packages.

Editors' Recommendations

Hillary K. Grigonis
Hillary never planned on becoming a photographer—and then she was handed a camera at her first writing job and she's been…
Best Alienware deals: Gaming PCs, laptops, and monitors
Alienware Aurora R15 placed at an angle on a table.

If you're looking to pick up a new gaming laptop, gaming PC, headset, or even a gaming chair, Alienware has a huge variety of items on offer for you, with some really high-end gear that is synonymous with the brand. That said, you do tend to pay a premium price for Alienware, given its position in the market as the maker of fancy gear, so if you want to pick something up, you'll likely want to rely on a good deal. Luckily, there are a lot of excellent deals floating around on Alienware products, and we've gone out and collected some of our favorites below, although if you can't quite find what you are looking for, check out these great best gaming laptop deals and best gaming PC deals as well.
Alienware AW720H wireless gaming headset -- $130, was $150

A gaming headset is a great way to keep in touch with your friends while you play. The Alienware AW720H gaming headset lets you do so without the burden of wires, as it connects to your gaming setup via Bluetooth. It has a built-in microphone for outgoing communications, as well as Dolby Atmos, Surround Sound, and Stereo Sound options to help immerse you in the game and incoming communications.

Read more
Is Dashlane safe? Here’s what we know about its security history
Dashlane website on a laptop.

If you’re looking for a password manager and come across Dashlane in your search, you’re probably wondering how safe it is to use. After all, similar companies and products have made headlines and become well-known for security incidents.

Here, we’ll look at the security measures Dashlane uses for its infrastructure, as well as safety features it provides to its users. You can then decide how safe you would feel using Dashlane as your go-to password tool.
What is Dashlane?

Read more
Nvidia ARM laptops may be in the works, and that could change everything
Intel and Nvidia badges on the Asus ROG Zephyrus G16.

Imagine a laptop with an iteration of Nvidia’s ARM-based CPU combined with a powerful RTX graphics card, all enhanced by AI. Years ago, that would have sounded outlandish, but now it seems like it could actually happen.

In a recent interview with Bloomberg, Nvidia CEO Jensen Huang and Dell CEO Michael Dell more or less confirmed that Team Green will enter the AI-PC hype next year.

Read more