Skip to main content

Hackers could have credit card numbers of 880,000 Orbitz users

Hackers may have gained access to as many as 880,000 credit cards by hacking into the Orbitz website. On Tuesday, March 20, the Expedia-owned travel-booking company shared that it had found evidence of a hacker gaining access to user data. The company doesn’t have evidence that the information was actually taken, but the access means user data could have been stolen.

The hack could include data from travelers that used the platform between January 1 and June 22, 2016. Partner programs using Orbitz have a much wider date range for vulerability, extending to Dec. 22, 2017. Orbitz said that, along with billing information, the hack also could have exposed other personal data including names, emails, phone numbers, billing addresses, and gender. The company’s investigation also suggests that travel itineraries, passport information, and social security numbers were not part of the hack.

The hacker gained access to an older version of the website, according to the company. The current booking platform is not part of that breach, Orbitz said.

Orbitz discovered the hack earlier in March and since has launched an investigation to determine what data could have been affected. After discovering the vulnerability, the company said it hired a forensic investigative firm and also involved law enforcement.

In a statement, Orbitz said, “We deeply regret the incident, and we are committed to doing everything we can to maintain the trust of our customers and partners.”

Willy Leichtera, a cybersecurity expert with Virsec Systems, lauded the company for the promptness of its disclosure, but noted that access to the “older” site is just as troubling.

“First, it’s important to point out the Orbitz announced this breach relatively quickly – within 3 weeks. That may not sound fast, but compared to Equifax (6+ months) and Uber (never, until they got caught), Orbitz did the right thing.”

“What’s more unsettling is the idea that sensitive data for close to a million customers was available in a ‘legacy website.’ That makes it sound like it’s OK to neglect security on older systems while you focus on your latest, coolest apps. If it’s a public-facing website with real data, it’s not legacy – it’s live, and a real liability.”

For those 880,000 users that could have compromised data, the company is offering a year of credit and identity monitoring at no charge. Orbitz says it is notifying users that could have been affected by the breach, but travelers that booked within those dates can also call 855-828-3959 in the U.S. or 512-201-2214 outside the U.S. for additional information.

The breach isn’t the first time hackers have targeted travel platforms. Sabre announced a hack last year on the hotel booking platform. In 2011, a TripAdvisor hack compromised user emails, but the booking platform didn’t collect payment information from users.

Orbitz is owned by Expedia Inc. and offers online booking for flights, accommodations, and rental cars, as well as options like cruises and complete travel packages.

Editors' Recommendations

Hillary K. Grigonis
Hillary never planned on becoming a photographer—and then she was handed a camera at her first writing job and she's been…
How to draw on Google Docs to add doodles, sketches, and more
The Google Play Store, YouTube, and Google Docs installed on an Amazon Fire Max 11.

Word processing software isn’t the kind of tool that most users would consider exciting, which is why we’re glad to see companies like Google adding a little flair to its own products. We’re talking about Google Docs, a free-to-use word processor that’s part of your larger Google Account ecosystem. Basic formatting options and other familiar word processing functions are front and center on Google Docs, but the ability to add doodles, sketches, and other entertaining media to your next Docs file requires a special bit of know-how.

Read more
AMD’s upcoming APUs might destroy your GPU
AMD CEO Lisa Su holding an APU chip.

The spec sheets for AMD's upcoming APU lineups, dubbed Strix Point and Strix Halo, have just been leaked, and it's safe to say that they're looking pretty impressive. Equipped with Zen 5 cores, the new APUs will find their way to laptops that are meant to be on the thinner side, but their performance might rival that of some of the best budget graphics cards -- and that's without having a discrete GPU.

While AMD hasn't unveiled Strix Point (STX) and Strix Halo (STX Halo) specs just yet, they were leaked by HKEPC and then shared by VideoCardz. The sheet goes over the maximum specs for each APU lineup, the first of which, Strix Point, is rumored to launch this year. Strix Halo, said to be significantly more powerful, is currently slated for a 2025 release.

Read more
Hyte made me fall in love with my gaming PC all over again
A PC built with the Hyte Nexus Link ecosystem.

I've never seen anything quite like Hyte's new Nexus Link ecosystem. Corsair has its iCue Link system, and Lian Li has its magnetic Uni system, and all three companies are now offering ways to tie together your PC cooling and lighting devoid of extraneous cables. But Hyte's marriage of hardware, software, and accessories is in a league of its own -- and it transformed my PC build completely.

I've been using some of the foundational components of the ecosystem for about a week, retailoring a build inside of Hyte's own Y40 PC case to see how the system works. It doesn't seem too exciting at first -- Hyte released an all-in-one (AIO) liquid cooler, some fans, and a few RGB strips, who cares? But as I engaged more with the Nexus Link ecosystem, I only became more impressed.
It all starts with the cooler

Read more