HackingStolen CredentialsCustomer Data InvolvedPIIFINANCIAL_ACCOUNTLowContained
American Express Travel Related Services Company, Inc. and/or its Affiliates
bd_091050a6b0c2f949 · schema v1 · pii pii-v1
Full breach record for American Express Travel Related Services Company, Inc. and/or its Affiliates →American Express Travel Related Services Company, Inc. reported a data security breach involving unauthorized access to a merchant's website files. The incident compromised cardholder data, including American Express account numbers, names, and expiration dates. Social Security numbers were not impacted, and no unauthorized activity was detected on card accounts. The company placed additional fraud monitoring on affected cards and notified cardholders via letter.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e0f4d149a07c0e3fCalifornia State AGfiled 2014-12-19(27d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-48072
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 15, 2015
- Raw hash
- 31ebb2b2ef7854187b9246e6661056e3a35f7477fccb409c5278b26c38d6fcac
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Victim entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.