CHICAGO — Travel fare aggregator Orbitz says one of its older websites may have been hacked, potentially exposing the personal information of people who made purchases online between Jan. 1, 2016 and Dec. 22, 2017.

Orbitz said Tuesday that about 880,000 payment cards were affected. Data that was likely exposed includes name, address, payment card information, date of birth, phone number, email address and gender. Social Security information was not hacked, however.

The company said evidence suggests that an attacker may have accessed information stored on the platform – which was for both consumers and business partners – between Oct. 1, 2017 and Dec. 22, 2017. It said it discovered the data breach March 1.

The current website was not involved in the incident. Orbitz is now owned by Expedia Inc. of Belleview, Washington.

Orbitz is offering those affected a year of free credit monitoring and identity protection service in countries where available.

Only subscribers are eligible to post comments. Please subscribe or login first for digital access. Here’s why.

Use the form below to reset your password. When you've submitted your account email, we will send an email with a reset code.

filed under: