HackingFinancial ServicesFinanceSupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedPCIFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
American Express Travel Related Services Company, Inc. and/or its Affiliates
bd_0bb5047efb6adbfc · schema v1 · pii pii-v1
Full breach record for American Express Travel Related Services Company, Inc. and/or its Affiliates →A merchant that processed American Express card payments experienced unauthorized access to its data files. Affected data included cardmember account numbers, names, and card expiration dates. Social Security numbers were not impacted. American Express placed additional fraud monitoring on affected cards and notified impacted cardmembers. The breach date was reported as May 21, 2012.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_de6880d59774c15dCalifornia State AGfiled 2012-11-30(10d gap)Candidate
- bd_afb8ec1e7dd13398California State AGfiled 2012-10-10(41d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-37010
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 20, 2012
- Raw hash
- e4630307f413966272f0320f18c3b7aaecbaac40ab6c50e38f19513083e871e7
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Victim entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
- Industry
- Financial Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1530 Data from Cloud Storage Object
- Threat actor
- ExternalFinancial
- Regulator citations
- Notification submitted to California Attorney General
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.