HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Orbitz Worldwide, LLC
bd_b9294a8e6ae14d2c · schema v1 · pii pii-v1
Full breach record for Orbitz Worldwide, LLC →Orbitz notified California AG in March 2018 regarding a breach of its legacy travel booking platform occurring between Oct 1 and Dec 22, 2017. Attackers likely accessed personal information including names, payment card info, DOB, phone, email, and address for purchases made in early 2016. SSNs were not involved. Orbitz engaged forensic investigators and law enforcement, enhanced security, and offered one year of credit monitoring.
California clockDiscovered Mar 1, 2018 → Notified Mar 22, 201821d ✓ CA 60-day OK20 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_167ffa75ae444821Oregon State AGfiled 2018-03-21Verified
- bd_73f028e269ca8c3aCalifornia State AGfiled 2018-03-22(1d gap)Verified
- bd_2883e555dee90b7fWashington State AGfiled 2018-03-20(1d gap)Candidate
- bd_f4cde765419b2010California State AGfiled 2018-04-20(30d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-134667
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 21, 2018
- Raw hash
- 50c7885a230733c68c39cc6b02fda7d8f1ed30c08e72aba060c1014363bc463c
Reporting entity
- Name
- Orbitz Worldwide, LLCnorm: orbitz worldwide
Victim entity
- Name
- Orbitz Worldwide, LLCnorm: orbitz worldwide
Incident
- Discovered
- Mar 1, 2018
- Materiality determined
- —
- Notification sent
- Mar 22, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 days(20 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 21d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 1, 2018→ Notified: Mar 22, 201821d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.