Skip to main content

Hackers could have credit card numbers of 880,000 Orbitz users

Hackers may have gained access to as many as 880,000 credit cards by hacking into the Orbitz website. On Tuesday, March 20, the Expedia-owned travel-booking company shared that it had found evidence of a hacker gaining access to user data. The company doesn’t have evidence that the information was actually taken, but the access means user data could have been stolen.

The hack could include data from travelers that used the platform between January 1 and June 22, 2016. Partner programs using Orbitz have a much wider date range for vulerability, extending to Dec. 22, 2017. Orbitz said that, along with billing information, the hack also could have exposed other personal data including names, emails, phone numbers, billing addresses, and gender. The company’s investigation also suggests that travel itineraries, passport information, and social security numbers were not part of the hack.

The hacker gained access to an older version of the website, according to the company. The current booking platform is not part of that breach, Orbitz said.

Orbitz discovered the hack earlier in March and since has launched an investigation to determine what data could have been affected. After discovering the vulnerability, the company said it hired a forensic investigative firm and also involved law enforcement.

In a statement, Orbitz said, “We deeply regret the incident, and we are committed to doing everything we can to maintain the trust of our customers and partners.”

Willy Leichtera, a cybersecurity expert with Virsec Systems, lauded the company for the promptness of its disclosure, but noted that access to the “older” site is just as troubling.

“First, it’s important to point out the Orbitz announced this breach relatively quickly – within 3 weeks. That may not sound fast, but compared to Equifax (6+ months) and Uber (never, until they got caught), Orbitz did the right thing.”

“What’s more unsettling is the idea that sensitive data for close to a million customers was available in a ‘legacy website.’ That makes it sound like it’s OK to neglect security on older systems while you focus on your latest, coolest apps. If it’s a public-facing website with real data, it’s not legacy – it’s live, and a real liability.”

For those 880,000 users that could have compromised data, the company is offering a year of credit and identity monitoring at no charge. Orbitz says it is notifying users that could have been affected by the breach, but travelers that booked within those dates can also call 855-828-3959 in the U.S. or 512-201-2214 outside the U.S. for additional information.

The breach isn’t the first time hackers have targeted travel platforms. Sabre announced a hack last year on the hotel booking platform. In 2011, a TripAdvisor hack compromised user emails, but the booking platform didn’t collect payment information from users.

Orbitz is owned by Expedia Inc. and offers online booking for flights, accommodations, and rental cars, as well as options like cruises and complete travel packages.

Editors' Recommendations

Hillary K. Grigonis
Hillary never planned on becoming a photographer—and then she was handed a camera at her first writing job and she's been…
These are the 10 best gaming monitors of 2024
The back of the Alienware 32 QD-OLED.

There are a ton of options if you are on the hunt for one of the best gaming monitors, but for us, Alienware's 34 QD-OLED still takes the cake in 2024. It's not the display for everyone, though, and after reviewing dozens of the top gaming monitors, we've settled on a list of displays that offer great gaming performance for any budget or purpose.

We're focused specifically on gaming monitors here, which come with higher refresh rates and adaptive sync features like G-Sync and FreeSync. If you're looking for an all-around display, make sure to browse our list of the best monitors.

Read more
If you use a VPN, don’t skip this important Windows 11 update
Microsoft Surface Laptop Go 3 rear view showing lid and logo.

It's not you; Windows is causing the issues this time. If the VPN on your Windows 11 or Windows 10 computer is having a hard time connecting, it is likely because of Microsoft's April security updates for Windows 11 (KB5036893 for) and Windows 10 (KB5036892), which have been reported to be the cause of the problems.

But there's good news. According to Microsoft, a patch is now available to fix the VPN problems users are experiencing.

Read more
This Lenovo 2-in-1 laptop is discounted from $970 to $640
The Lenovo IdeaPad Flex 5 against a white backdrop.

If you can’t decide between a laptop or a tablet, Lenovo has the laptop deals for you, with a huge discount on the Lenovo IdeaPad Flex 5 2-in-1 laptop. Ordinarily priced at $970, it’s down to $640 at Lenovo, so you’re saving $330. Lenovo's estimated value prices can be a little optimistic, but this is a good value regardless. Whatever the discount, we do know that $640 for this laptop is pretty sweet. Here’s what you need to know about it before you buy.

Why you should buy the Lenovo IdeaPad Flex 5
Lenovo makes some of the best 2-in-1 laptops knowing how to get the most from the concept. This particular model has an AMD Ryzen 7 7730U processor paired up with 16GB of memory and 1TB of SSD storage so it’s pretty capable of handling a lot of your working needs.

Read more