Expedia's travel website, Orbitz, said that 100 of thousands of users were impacted by a security compromise.
According to Orbitz, hackers were able to obtain access to an outdated platform and pilfer financial and personal information from customers and business associates.
All of the following information is disclosed: full name, date of birth, gender, phone number, email address, billing and physical addresses, and credit card information. Approximately 880,000 credit cards were impacted by the security issue, according to Orbitz.
There is no proof that the existing version of Orbitz.com is impacted, and the breach did not reveal passport or trip itinerary information.
Source: https://securityaffairs.com/70499/data-breach/orbitz-data-breach.html
TPRM report: https://scoringcyber.rankiteo.com/company/orbitz
"id": "orb52181223",
"linkid": "orbitz",
"type": "Breach",
"date": "03/2018",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization’s existence"
{'affected_entities': [{'customers_affected': 'hundreds of thousands',
'industry': 'Travel',
'name': 'Orbitz',
'type': 'Travel Website'}],
'attack_vector': 'Access to outdated platform',
'data_breach': {'personally_identifiable_information': ['full name',
'date of birth',
'gender',
'phone number',
'email address',
'billing and physical '
'addresses'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['full name',
'date of birth',
'gender',
'phone number',
'email address',
'billing and physical addresses',
'credit card information']},
'description': "Expedia's travel website, Orbitz, disclosed a security "
'compromise affecting hundreds of thousands of users. Hackers '
'accessed an outdated platform to steal financial and personal '
'information from customers and business associates. The '
'compromised data includes full name, date of birth, gender, '
'phone number, email address, billing and physical addresses, '
'and credit card information. Approximately 880,000 credit '
'cards were impacted.',
'impact': {'data_compromised': ['full name',
'date of birth',
'gender',
'phone number',
'email address',
'billing and physical addresses',
'credit card information'],
'payment_information_risk': ['880,000 credit cards']},
'initial_access_broker': {'entry_point': 'outdated platform'},
'threat_actor': 'Unknown Hackers',
'title': 'Orbitz Data Breach',
'type': 'Data Breach'}