Orbitz Worldwide, LLC
bd_f4cde765419b2010 · schema v1 · pii pii-v1
Full breach record for Orbitz Worldwide, LLC →Southwest Airlines co. reported a data breach involving its legacy Orbitz travel booking platform. Between October 1, 2017, and December 22, 2017, an unauthorized third party accessed personal information of customers who made hotel reservations through Southwest.com. Affected data included names, payment card numbers, expiration dates, phone numbers, email addresses, and billing addresses. Southwest confirmed its own systems were not affected. Orbitz engaged forensic investigators and law enforcement, enhanced security, and offered one year of credit monitoring to affected individuals.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_73f028e269ca8c3aCalifornia State AGfiled 2018-03-22(29d gap)Verified
- bd_167ffa75ae444821Oregon State AGfiled 2018-03-21(30d gap)Verified
- bd_b9294a8e6ae14d2cCalifornia State AGfiled 2018-03-21(30d gap)Candidate
- bd_2883e555dee90b7fWashington State AGfiled 2018-03-20(31d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-135515
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 20, 2018
- Raw hash
- 542c5d436882f7438cab579a67a7133ac957701636f47181fcae30132431a501
Reporting entity
- Name
- Southwest Airlines Co.norm: southwest airlines
Victim entity
- Name
- Orbitz Worldwide, LLCnorm: orbitz worldwide
Incident
- Discovered
- Mar 1, 2018
- Materiality determined
- Apr 20, 2018
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.