Expedia's Orbitz says it was hacked, giving the attacker access to customer data, including ~880,000 payment cards in total from January 2016 to December 2017
The travel booking site said about 880,000 payment cards were affected. — Travel booking website Orbitz has been hacked, the company said.
Context & Ripple Effects
Orbitz, Expedia's travel-booking brand, is disclosing an intrusion that gave an attacker access to customer data — including roughly 880,000 payment cards — over a two-year window from January 2016 to December 2017. The disclosure lands in the middle of a run of payment-card thefts across travel and hospitality: earlier in the same period, Hyatt reported malware infecting the payment systems of some 300 hotels across 54 countries.
The pattern did not stop here. Months later, British Airways disclosed a site and app attack exposing customers' personal and financial details, and by late 2020 a breach at Prestige Software leaked data on millions of customers of Booking.com, Expedia, Hotels.com and other platforms — putting Expedia's brands on both sides of the recurring problem.
First-order effects
- Customers whose cards were in the exposed set face immediate fraud risk and likely reissuance, while Expedia absorbs notification costs and hard questions about why a 2016–2017 compromise surfaced only in March 2018.
Second-order effects
- Banks and card networks shoulder the reissuance and monitoring burden, and every rival booking platform — already singed by the Hyatt and Zomato incidents — is pushed to accelerate security audits of its own reservation and payment flows.
Third-order effects
- If the pattern holds, long-dwell intrusions into travel and hospitality payment systems become a structural cost of the category, strengthening the case for regulators to tighten breach-disclosure timelines and for platforms to compete on security posture as much as price.
The trend: Consumer travel and hospitality platforms are becoming a repeat target class for payment-card theft, with multi-year gaps between intrusion and disclosure defining the industry's security reckoning.