Orbitz Worldwide, LLC
ent_019e5b5c48bd95a7fb48e79921813e32
Disclosures
6
State AG · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
328,612
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Orbitz Worldwide, LLC
- Normalized
- orbitz worldwide— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300JPNH9MBSIY6N93
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- 🐻California State AGas victim2018-04-20
Southwest Airlines co. reported a data breach involving its legacy Orbitz travel booking platform. Between October 1, 2017, and December 22, 2017, an unauthorized third party accessed personal information of customers who made hotel reservations through Southwest.com. Affected data included names, payment card numbers, expiration dates, phone numbers, email addresses, and billing addresses. Southwest confirmed its own systems were not affected. Orbitz engaged forensic investigators and law enforcement, enhanced security, and offered one year of credit monitoring to affected individuals.
- 🌺Hawaii State AGas victim2018-04-04
Orbitz, LLC reported a data breach to the Hawaii Office of Consumer Protection. The office was notified on 2018/04.04. Breach type: Hackers/Unauthorized Access. 1,078 Hawaii residents were affected. Recovered from the Internet Archive after the notice was removed from the OCP table.
- 🐻California State AGas victim2018-03-22
American Express Travel Related Services Company, Inc. reported a data breach involving its third-party vendor, Orbitz. The incident affected the Orbitz booking platform, impacting transactions from January 1, 2016, through December 22, 2017. The breach exposed customer personal information, including names, payment card details, dates of birth, phone numbers, email addresses, and physical/billing addresses. American Express notified affected individuals, offering two years of Experian IdentityWorks and fraud monitoring. The Orbitz platform has been remediated.
- 🦫Oregon State AGas victim2018-03-21
Orbitz reported a data breach to the Oregon Attorney General. The breach was reported on 2018-03-21. The breach occurred during 10/1/2017 - 12/22/2017. The breach was discovered on 3/1/2018. 328,612 individuals were affected. Notice was sent on 3/22/20183/23/2018.
- 🐻California State AGas victim2018-03-21
Orbitz notified California AG in March 2018 regarding a breach of its legacy travel booking platform occurring between Oct 1 and Dec 22, 2017. Attackers likely accessed personal information including names, payment card info, DOB, phone, email, and address for purchases made in early 2016. SSNs were not involved. Orbitz engaged forensic investigators and law enforcement, enhanced security, and offered one year of credit monitoring.
- 🌲Washington State AGas victim2018-03-20
Orbitz, a business sector entity reported a unclear/unknown incident to the Washington Attorney General. The organization became aware of the incident on 2018-03-01 and filed notice on 2018-03-20. 5,013 Washington residents were affected. 19 days elapsed between awareness and notification. 151 days to identify the breach. 0 days to contain the breach.