HackingCustomer Data InvolvedPIIFINANCIAL_ACCOUNTLowContained
American Express Travel Related Services Company, Inc. and/or its Affiliates
bd_109d68ce96252abd · schema v1 · pii pii-v1
Full breach record for American Express Travel Related Services Company, Inc. and/or its Affiliates →American Express Travel Related Services Company, Inc. reported a data breach affecting cardholders. Unauthorized access to a merchant's website files resulted in the exposure of card account numbers, names, and expiration dates. Social Security numbers were not impacted. The breach date was August 24, 2012, and the notification was filed with the California AG on December 5, 2012.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_e23027a6db534655California State AGfiled 2013-03-26(35d gap)Candidate
- bd_2f0d53851a644835California State AGfiled 2013-01-11(39d gap)Candidate
- bd_db62fa20db2e76acCalifornia State AGfiled 2013-04-04(44d gap)Candidate
- bd_37cf6b069cfc1f5dCalifornia State AGfiled 2013-05-02(72d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 83d gap
- bd_8f2c57dc544bccd9California State AGfiled 2013-05-13(83d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-38941
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 19, 2013
- Raw hash
- 019d7b108a8073fbe45d3c40be347ba982f2aaabce8b987204874577ef448bb5
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Victim entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Incident
- Discovered
- Dec 5, 2012
- Materiality determined
- Dec 5, 2012
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(76 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.