An Orbitz data breach that occurred on a legacy booking
platform and a partner's platform last year impacted approximately 880,000
payment cards, the OTA said on Tuesday.
An Orbitz spokesperson said the platform in question was
part of Orbitz when it was acquired by Expedia Inc. in 2015. Orbitz has since
migrated to the Expedia platform, which was not affected by the breach.
An attacker could have had access to full name, payment card
information, date of birth, phone number, email address, physical address and
gender, but Orbitz said "to date, we do not have direct evidence that this
personal information was actually taken from the platform."
No evidence was found of unauthorized access to other data,
like itinerary or passport information.
Orbitz said it was conducting an investigation on the "legacy
Orbitz platform" earlier this month when it found evidence that "an
attacker may have accessed personal information stored on this consumer and
business partner platform" between Oct. 1-Dec. 22, 2017.
"We took immediate steps to investigate the incident
and enhance security and monitoring of the affected platform," Orbitz said
in a statement. That included bringing in law enforcement, cybersecurity
experts and a third-party forensic investigation firm. Orbitz said it "took
swift action to eliminate and prevent unauthorized access to the platform."
The hacker could have accessed personal information from the
consumer platform data on purchases made between Jan. 1-June 22, 2016, and could
have accessed personal information from the partner platform data on purchases
made between Jan. 1, 2016, and Dec. 22, 2017.
Orbitz did not name the partner.
"Ensuring the safety and security of the personal data
of our customers and our partners' customers is very important to us," Orbitz
said. "We deeply regret the incident, and we are committed to doing
everything we can to maintain the trust of our customers and partners."
The company is in the process of notifying customers and
partners who may have been impacted, and is offering a year of credit-monitoring
and identity-protection services. Orbitz is also offering to inform partners'
customers.
Orbitz has set up a hotline for customer questions open from
8 a.m. To 8 p.m. Central time Monday through Saturday: 1-855-828-3959. It has
also set up a website with information on the incident https://orbitz.allclearid.com.