HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Orbitz Worldwide, LLC
bd_73f028e269ca8c3a · schema v1 · pii pii-v1
Full breach record for Orbitz Worldwide, LLC →American Express Travel Related Services Company, Inc. reported a data breach involving its third-party vendor, Orbitz. The incident affected the Orbitz booking platform, impacting transactions from January 1, 2016, through December 22, 2017. The breach exposed customer personal information, including names, payment card details, dates of birth, phone numbers, email addresses, and physical/billing addresses. American Express notified affected individuals, offering two years of Experian IdentityWorks and fraud monitoring. The Orbitz platform has been remediated.
California clockDiscovered Mar 16, 2018 → Notified Mar 16, 20180d ✓ CA 60-day OK6 days discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_167ffa75ae444821Oregon State AGfiled 2018-03-21(1d gap)Verified
- bd_b9294a8e6ae14d2cCalifornia State AGfiled 2018-03-21(1d gap)Candidate
- bd_2883e555dee90b7fWashington State AGfiled 2018-03-20(2d gap)Candidate
- bd_f4cde765419b2010California State AGfiled 2018-04-20(29d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-134720
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 22, 2018
- Raw hash
- 1e0cea93e27c878a4cf3ba61789118e51ee80e7f7f91fb0fe1e8c7f55ead45eb
Reporting entity
- Name
- AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.norm: american express travel related
Victim entity
- Name
- Orbitz Worldwide, LLCnorm: orbitz worldwide
Incident
- Discovered
- Mar 16, 2018
- Materiality determined
- —
- Notification sent
- Mar 16, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Third party
- via Orbitz
- Initial access
- supply_chain
Compliance
- Time to disclose
- 6 days(6 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 16, 2018→ Notified: Mar 16, 20180d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.