CHICAGO — Travel fare aggregator Orbitz says one of its older websites may have been hacked, potentially exposing the personal information of people who made purchases online between Jan. 1, 2016 and Dec. 22, 2017.

Orbitz said Tuesday that about 880,000 payment cards were affected. Data that was likely exposed includes name, address, payment card information, date of birth, phone number, email address and gender. Social Security information was not hacked, however.

The company said evidence suggests that an attacker may have accessed information stored on the platform – which was for both consumers and business partners – between Oct. 1, 2017 and Dec. 22, 2017. It said it discovered the data breach March 1.

The current website was not involved in the incident. Orbitz is now owned by Expedia Inc. of Belleview, Washington.

Orbitz is offering those affected a year of free credit monitoring and identity protection service in countries where available.

Comments are not available on this story.

filed under: