Clustered 5 filings across 3 jurisdictions · filing window Mar 20, 2018 → Apr 20, 2018. View entity profile → Other incidents for this victim →
incident inc_de0a402bca3c418a · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA OR WA
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
Oct 1, 2017 → Dec 22, 2017
When the intrusion reportedly occurred, per the linked filings
Mar 1, 2018
Reported by WASHINGTON AG, OREGON AG, CALIFORNIA AG filings
Mar 16, 2018
Reported by CALIFORNIA AG filing
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Orbitz, a business sector entity reported a unclear/unknown incident to the Washington Attorney General. The organization became aware of the incident on 2018-03-01 and filed notice on 2018-03-20. 5,013 Washington residents were affected. 19 days elapsed between awareness and notification. 151 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 5,013
Orbitz reported a data breach to the Oregon Attorney General. The breach was reported on 2018-03-21. The breach occurred during 10/1/2017 - 12/22/2017. The breach was discovered on 3/1/2018. 328,612 individuals were affected. Notice was sent on 3/22/20183/23/2018.
Affected (this filing): 328,612
Orbitz notified California AG in March 2018 regarding a breach of its legacy travel booking platform occurring between Oct 1 and Dec 22, 2017. Attackers likely accessed personal information including names, payment card info, DOB, phone, email, and address for purchases made in early 2016. SSNs were not involved. Orbitz engaged forensic investigators and law enforcement, enhanced security, and offered one year of credit monitoring.
American Express Travel Related Services Company, Inc. reported a data breach involving its third-party vendor, Orbitz. The incident affected the Orbitz booking platform, impacting transactions from January 1, 2016, through December 22, 2017. The breach exposed customer personal information, including names, payment card details, dates of birth, phone numbers, email addresses, and physical/billing addresses. American Express notified affected individuals, offering two years of Experian IdentityWorks and fraud monitoring. The Orbitz platform has been remediated.
Southwest Airlines co. reported a data breach involving its legacy Orbitz travel booking platform. Between October 1, 2017, and December 22, 2017, an unauthorized third party accessed personal information of customers who made hotel reservations through Southwest.com. Affected data included names, payment card numbers, expiration dates, phone numbers, email addresses, and billing addresses. Southwest confirmed its own systems were not affected. Orbitz engaged forensic investigators and law enforcement, enhanced security, and offered one year of credit monitoring to affected individuals.