Skip to main content

Hackers could have credit card numbers of 880,000 Orbitz users

Hackers may have gained access to as many as 880,000 credit cards by hacking into the Orbitz website. On Tuesday, March 20, the Expedia-owned travel-booking company shared that it had found evidence of a hacker gaining access to user data. The company doesn’t have evidence that the information was actually taken, but the access means user data could have been stolen.

The hack could include data from travelers that used the platform between January 1 and June 22, 2016. Partner programs using Orbitz have a much wider date range for vulerability, extending to Dec. 22, 2017. Orbitz said that, along with billing information, the hack also could have exposed other personal data including names, emails, phone numbers, billing addresses, and gender. The company’s investigation also suggests that travel itineraries, passport information, and social security numbers were not part of the hack.

The hacker gained access to an older version of the website, according to the company. The current booking platform is not part of that breach, Orbitz said.

Orbitz discovered the hack earlier in March and since has launched an investigation to determine what data could have been affected. After discovering the vulnerability, the company said it hired a forensic investigative firm and also involved law enforcement.

In a statement, Orbitz said, “We deeply regret the incident, and we are committed to doing everything we can to maintain the trust of our customers and partners.”

Willy Leichtera, a cybersecurity expert with Virsec Systems, lauded the company for the promptness of its disclosure, but noted that access to the “older” site is just as troubling.

“First, it’s important to point out the Orbitz announced this breach relatively quickly – within 3 weeks. That may not sound fast, but compared to Equifax (6+ months) and Uber (never, until they got caught), Orbitz did the right thing.”

“What’s more unsettling is the idea that sensitive data for close to a million customers was available in a ‘legacy website.’ That makes it sound like it’s OK to neglect security on older systems while you focus on your latest, coolest apps. If it’s a public-facing website with real data, it’s not legacy – it’s live, and a real liability.”

For those 880,000 users that could have compromised data, the company is offering a year of credit and identity monitoring at no charge. Orbitz says it is notifying users that could have been affected by the breach, but travelers that booked within those dates can also call 855-828-3959 in the U.S. or 512-201-2214 outside the U.S. for additional information.

The breach isn’t the first time hackers have targeted travel platforms. Sabre announced a hack last year on the hotel booking platform. In 2011, a TripAdvisor hack compromised user emails, but the booking platform didn’t collect payment information from users.

Orbitz is owned by Expedia Inc. and offers online booking for flights, accommodations, and rental cars, as well as options like cruises and complete travel packages.

Editors' Recommendations

Hillary K. Grigonis
Hillary never planned on becoming a photographer—and then she was handed a camera at her first writing job and she's been…
Apple Memorial Day sales: Save on Apple Watch, iPad, MacBook, and more
The 14-inch MacBook Pro with M3 Max chip seen from behind.

Most of this year's Memorial Day deals are set to launch very soon, but if you want to get your shopping for Apple devices done early, we're here to help you out with this roundup of the early Apple Memorial Day sales that are already available. Whether you're planning to buy a new iPad, iPhone, AirPods, MacBook, or Apple Watch, we've got some excellent bargains below. If anything catches your eye. it's highly recommended that you complete your purchase as soon as possible because there's no telling how soon these offers will expire -- some may not even make it to Memorial Day itself!
Best Memorial Day iPad deals

Memorial Day is one of the best times of the year to search for iPad deals. There are some fantastic discounts that are available across a variety of models of Apple's tablet, including the entry-level Apple iPad and the creatives-focused Apple iPad Pro, so whatever your purpose is for thinking about getting an iPad, there won't be any shortage of options for you here.

Read more
I ask again: Will Apple ever merge the Mac and iPad?
An Apple iPad and a MacBook together on a desk alongside a pair of headphones.

Every few months, we hear the same argument being made: Apple should bring the Mac and the iPad closer together -- or even merge them and their operating systems completely -- to create some sort of hybrid device that would solve all of Apple’s problems. While I don’t entirely agree with these assessments, they do provide an interesting look into how your Apple devices might work in the coming years.

Bloomberg’s Mark Gurman is the latest to throw his hat into the ring, and the reporter’s Power On newsletter has detailed what he believes Apple should do to shape the future of the Mac and the iPad.

Read more
HP just reset its entire PC lineup
The HP OmniBook X AI PC.

In the new AI PC era, HP is starting fresh with an entirely new branding structure to highlight the power and performance of a fresh set of computers.

While many people may be familiar with the company’s Pavilion, Envy, and Spectre products on the consumer side and the Dragonfly devices for enterprise options, HP will now retire these lines and overhaul its options under two main lines: consumer and commercial. These include the Omni brand for consumers and the Elite brand for commercial. The company unveiled its inaugural products for each line, the HP OmniBook X AI PC and HP EliteBook Ultra AI PC, on Monday during Microsoft’s AI Vision event. I got to see the new devices ahead of the event and check out how this new branding and design looks in person.
A new beginning
These models will be the beginning of an overall brand expansion for HP. On the consumer side, the company plans to have several forms and tiers of Omni products with the goal of making customer selection simpler. Notably, HP plans to keep its Omen gaming PC brand intact during this restructuring.

Read more