Company Details
expedia
None employees
234
5615
expedia.com
0
EXP_2829882
In-progress

Expedia Company CyberSecurity Posture
expedia.comExpedia is one of the world's leading full-service travel brands, helping travelers get the most out of every trip they take by making the travel process seamless. With Expedia, travelers can plan and book flights, hotels, vacation packages, and car rentals in one complete marketplace. Expedia offers intelligent tools, personalized recommendations, and a booking experience that saves you money – making it easier to explore the world. Use our mobile app or visit www.expedia.com to start your next adventure. Why choose Expedia? Expedia is your all-in-one travel shop, providing access to a large inventory of flights, hotels, vacation packages, activities and car rentals, with savings for every part of your trip.Our smart recommendation and comparison tools make for thoughtful travel planning. And with Expedia, you can bundle now or later and still get savings towards your trip, for a travel planning experience that moves with you. For Partners Expedia connects travel businesses with millions of engaged travelers worldwide. Our partner solutions help hotels, airlines, and service providers grow bookings, optimize visibility, and deliver exceptional guest experiences. Expedia is the flagship travel brand of Expedia Group.
Company Details
expedia
None employees
234
5615
expedia.com
0
EXP_2829882
In-progress
Between 750 and 799

Expedia Global Score (TPRM)XXXX

Description: Orbitz, a subsidiary of online travel agency Expedia Inc EXPE.O, said hackers may have accessed personal information from about 880,000 payment cards. The breach had occurred between Jan. 1, 2016 and Dec. 22, 2017 for its partner platform and between Jan. 1, 2016, and June 22, 2016, for its consumer platform. Information such as names, phone numbers, email and billing addresses have been accessed. For U.S. customers, social security numbers were not involved in this incident, the company said. The company said it has addressed the breach after it was discovered in March this year. Credit card issuer American Express Co AXP.N said in a statement that the attack did not compromise its platforms. Expedia’s shares fell as much as 1.9 percent to $108.99.
Description: On March 2, 2022, Expedia Group, Inc. disclosed a data breach that occurred on **March 24, 2021**, impacting **three individuals** whose **credit card information** was potentially compromised. The incident was categorized under the type '**Other**' in the breach classification. While the scale of the breach was limited—affecting only a small number of customers—Expedia responded by offering **12 months of identity theft protection services** through its **Expedia IdentityWorks** program to mitigate potential risks. The breach did not involve large-scale data exfiltration, systemic financial fraud, or broader reputational damage beyond the immediate notification and remediation efforts. No evidence suggested the compromised data was used for fraudulent activities, and the company’s operational continuity remained unaffected. The incident primarily highlighted vulnerabilities in payment data security, though the impact was confined to a minimal subset of users without escalating into wider systemic consequences.
Description: Nearly 300,000 Israelis' personal information was made public by an Iranian hacker organization targeting websites for Israeli travelers. The compromised information includes ID numbers, addresses, credit card details, and more from Israeli travel sites. The security of more than 20 travel-related websites was hacked, including hotel4u.co.il, hotels.co.il, isrotel.com, minihotel.co.il, trivago.co.il, and danhotels.com. They sent the data breach letters to all affected and asked them to be alerted.


No incidents recorded for Expedia in 2025.
No incidents recorded for Expedia in 2025.
No incidents recorded for Expedia in 2025.
Expedia cyber incidents detection timeline including parent company and subsidiaries

Expedia is one of the world's leading full-service travel brands, helping travelers get the most out of every trip they take by making the travel process seamless. With Expedia, travelers can plan and book flights, hotels, vacation packages, and car rentals in one complete marketplace. Expedia offers intelligent tools, personalized recommendations, and a booking experience that saves you money – making it easier to explore the world. Use our mobile app or visit www.expedia.com to start your next adventure. Why choose Expedia? Expedia is your all-in-one travel shop, providing access to a large inventory of flights, hotels, vacation packages, activities and car rentals, with savings for every part of your trip.Our smart recommendation and comparison tools make for thoughtful travel planning. And with Expedia, you can bundle now or later and still get savings towards your trip, for a travel planning experience that moves with you. For Partners Expedia connects travel businesses with millions of engaged travelers worldwide. Our partner solutions help hotels, airlines, and service providers grow bookings, optimize visibility, and deliver exceptional guest experiences. Expedia is the flagship travel brand of Expedia Group.


At Enterprise Mobility™ we are paving a new way forward by creating better experiences for how we move. We give people around the world the ability to connect in ways that suit their unique needs. It’s a bold idea that has defined our purpose-led, people-first organization for over 65 years, and it’

Hertz is one of the world’s largest mobility companies, and through its indirect subsidiary, The Hertz Corporation, operates the Hertz, Dollar, and Thrifty vehicle rental brands throughout North America, Europe, the Caribbean, Latin America, Africa, the Middle East, Asia, Australia, and New Zealand.

BCD Travel helps companies travel smart and achieve more. We drive program adoption, cost savings and talent retention through digital experiences that simplify business travel. Our 15,000+ dedicated team members service clients in 170+ countries as we shape a sustainable future for business travel.
Since our founding in 1972, Carnival Cruise Line — "The World’s Most Popular Cruise Line®” — carries millions of passengers every year. We offer a fun and unique career destination for a wide range of professionals in Marketing, IT, Accounting/Audit, Finance, Marine Operations and Human Resources, j

DER TOURISTIK GROUP AUF WACHSTUMSKURS Die DER Touristik Group gehört heute zu den führenden europäischen Reisekonzernen. Sie vereint unter ihrem Dach verschiedene Geschäftsfelder rund ums Thema Reisen und agiert seit 2018 strukturell als Holding mit vier Divisions. Durch den Zukauf der europäische
At Royal Caribbean Group, we deliver unforgettable vacations to guests who trust us with life’s greatest moments. We build the best ships, and even better careers, all while doing the right thing. We are passionate. We are innovative. We are unstoppable. We open the world to our employees. Your jour

Princess is the world’s leading premium cruise line operating a fleet of modern ships visiting over 380 destinations around the globe on more than 160 itineraries. Each moment on Princess is one of wonderful discovery where guests can relax and explore. The choices are endless, from invigorating act

Norwegian Cruise Line Holdings Ltd. (NYSE: NCLH) is a leading global cruise company which operates Norwegian Cruise Line, Oceania Cruises and Regent Seven Seas Cruises. With a combined fleet of 32 ships and approximately 66,500 berths, NCLH offers itineraries to approximately 700 destinations worl

CWT is a global business travel and meetings specialist, with whom companies and governments partner to keep their people connected, in traditional business locations and some of the most remote and inaccessible parts of the globe. A private company – owned through funds managed by a group of leadin
.png)
The tech layoff wave is still kicking in 2025. Last year saw more than 150,000 job cuts across 549 companies, according to independent...
SEATTLE, December 10, 2025--Expedia Group today announced it has entered into an agreement to acquire Tiqets, an Amsterdam-based global...
From left: Yotam Avrahami, Brian Lent, and John Kim. (VQ Capital Photo). Veteran tech operators with ties to Seattle are launching a new...
A Russian-speaking threat actor has orchestrated an extensive phishing campaign that has registered over 4300 malicious domains targeting...
Global phishing scam uses 4300 fake travel sites posing as hotel bookings to steal payment card data from unsuspecting travelers.
Cybersecurity researchers have called attention to a massive phishing campaign targeting the hospitality industry that lures hotel managers...
Sekoia, a cyber threat detection and response specialist, has released details on a widespread and ongoing cybercrime operation that first...
(Reuters) -Shares of Expedia rose 15% on Friday after the online travel agent forecast higher 2025 revenue and margin growth, banking on...
(Reuters) -Online travel platform Expedia (EXPE) boosted its forecast for 2025 revenue growth, after beating Wall Street estimates for...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Expedia is http://www.expedia.com.
According to Rankiteo, Expedia’s AI-generated cybersecurity score is 786, reflecting their Fair security posture.
According to Rankiteo, Expedia currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Expedia is not certified under SOC 2 Type 1.
According to Rankiteo, Expedia does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Expedia is not listed as GDPR compliant.
According to Rankiteo, Expedia does not currently maintain PCI DSS compliance.
According to Rankiteo, Expedia is not compliant with HIPAA regulations.
According to Rankiteo,Expedia is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Expedia operates primarily in the Travel Arrangements industry.
Expedia employs approximately None employees people worldwide.
Expedia presently has no subsidiaries across any sectors.
Expedia’s official LinkedIn profile has approximately 234 followers.
Expedia is classified under the NAICS code 5615, which corresponds to Travel Arrangement and Reservation Services.
No, Expedia does not have a profile on Crunchbase.
Yes, Expedia maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/expedia.
As of December 22, 2025, Rankiteo reports that Expedia has experienced 3 cybersecurity incidents.
Expedia has an estimated 4,816 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with sent data breach letters to all affected and asked them to be alerted., and remediation measures with offered 12 months of identity theft protection via expedia identityworks..
Title: Orbitz Data Breach
Description: Hackers may have accessed personal information from about 880,000 payment cards.
Date Detected: March 2018
Type: Data Breach
Title: Data Breach of Israeli Travel Websites
Description: Nearly 300,000 Israelis' personal information was made public by an Iranian hacker organization targeting websites for Israeli travelers.
Type: Data Breach
Attack Vector: Website Hacking
Threat Actor: Iranian Hacker Organization
Title: Expedia Group Data Breach (2021)
Description: The Maine Office of the Attorney General reported that Expedia Group, Inc. announced a data breach potentially affecting the credit card information of 3 individuals. Identity theft protection services were offered for 12 months through Expedia IdentityWorks.
Date Detected: 2022-03-02
Date Publicly Disclosed: 2022-03-02
Type: Other
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Names, Phone numbers, Email addresses, Billing addresses
Payment Information Risk: ['payment card information']

Data Compromised: Id numbers, Addresses, Credit card details
Systems Affected: hotel4u.co.ilhotels.co.ilisrotel.comminihotel.co.iltrivago.co.ildanhotels.com

Data Compromised: Credit card information
Identity Theft Risk: Yes (protection services offered)
Payment Information Risk: Yes
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Phone Numbers, Email Addresses, Billing Addresses, Payment Card Information, , Id Numbers, Addresses, Credit Card Details, , Credit Card Information and .

Entity Name: Orbitz
Entity Type: Subsidiary
Industry: Online Travel Agency
Customers Affected: 880000

Entity Type: Travel Websites
Industry: Travel
Location: Israel
Customers Affected: 300000

Entity Name: Expedia Group, Inc.
Entity Type: Corporation
Industry: Travel & Hospitality
Location: Seattle, Washington, USA
Customers Affected: 3

Communication Strategy: Sent data breach letters to all affected and asked them to be alerted.

Remediation Measures: Offered 12 months of identity theft protection via Expedia IdentityWorks

Type of Data Compromised: Names, Phone numbers, Email addresses, Billing addresses, Payment card information
Number of Records Exposed: 880000
Personally Identifiable Information: namesphone numbersemail addressesbilling addresses

Type of Data Compromised: Id numbers, Addresses, Credit card details
Number of Records Exposed: 300000
Personally Identifiable Information: ID numbersaddresses

Type of Data Compromised: Credit card information
Number of Records Exposed: 3
Sensitivity of Data: High
Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Offered 12 months of identity theft protection via Expedia IdentityWorks, .

Regulatory Notifications: Maine Office of the Attorney General

Source: Orbitz Disclosure

Source: Maine Office of the Attorney General
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Orbitz Disclosure, and Source: Maine Office of the Attorney General.
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Sent data breach letters to all affected and asked them to be alerted..

Customer Advisories: Offered 12 months of identity theft protection via Expedia IdentityWorks
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Offered 12 Months Of Identity Theft Protection Via Expedia Identityworks and .
Last Attacking Group: The attacking group in the last incident was an Iranian Hacker Organization.
Most Recent Incident Detected: The most recent incident detected was on March 2018.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2022-03-02.
Most Significant Data Compromised: The most significant data compromised in an incident were names, phone numbers, email addresses, billing addresses, , ID numbers, addresses, credit card details, , credit card information and .
Most Significant System Affected: The most significant system affected in an incident was hotel4u.co.ilhotels.co.ilisrotel.comminihotel.co.iltrivago.co.ildanhotels.com.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were credit card details, addresses, names, phone numbers, email addresses, credit card information, billing addresses and ID numbers.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 1.2K.
Most Recent Source: The most recent source of information about an incident are Orbitz Disclosure and Maine Office of the Attorney General.
Most Recent Customer Advisory: The most recent customer advisory issued was an Offered 12 months of identity theft protection via Expedia IdentityWorks.
.png)
Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client communicates user-controlled file paths to a privileged service, which performs file system operations without impersonating the requesting user. Due to improper privilege handling and a time-of-check time-of-use race condition combined with symbolic link and mount point manipulation, a local authenticated attacker can coerce the service into deleting arbitrary directories with SYSTEM privileges. This can be exploited to delete protected system folders such as C:\\Config.msi and subsequently achieve execution as NT AUTHORITY\\SYSTEM via MSI rollback techniques.
The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due to a missing capability check on the 'cs_update_application_status_callback' function in all versions up to, and including, 7.7. This makes it possible for authenticated attackers, with Candidate-level access and above, to inject cross-site scripting into the 'status' parameter of applied jobs for any user.
The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.7 via the 'cs_update_application_status_callback' due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Candidate-level access and above, to send a site-generated email with injected HTML to any user.
The FiboSearch – Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `thegem_te_search` shortcode in all versions up to, and including, 1.32.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability requires TheGem theme (premium) to be installed with Header Builder mode enabled, and the FiboSearch "Replace search bars" option enabled for TheGem integration.
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.0 via the ajax_get_members function. This is due to the use of a predictable low-entropy token (5 hex characters derived from md5 of post ID) to identify member directories and insufficient authorization checks on the unauthenticated AJAX endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including usernames, display names, user roles (including administrator accounts), profile URLs, and user IDs by enumerating predictable directory_id values or brute-forcing the small 16^5 token space.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.