HackingVulnerability ExploitCustomer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
American Express Travel Related Services Company, Inc. and/or its Affiliates
bd_1bbb7eb59417c055 · schema v1 · pii pii-v1
Full breach record for American Express Travel Related Services Company, Inc. and/or its Affiliates →American Express notified California residents that a merchant where they used their card detected unauthorized access to website files on May 28, 2013. Affected data included card account numbers, names, and expiration dates. Social Security numbers were not impacted. American Express placed additional fraud monitoring on affected cards and offered identity theft assistance.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_15bfd48c7b1ac692California State AGfiled 2013-12-13(1d gap)Candidate
- bd_015b86eaf80d46b1California State AGfiled 2013-12-04(8d gap)Candidate
- bd_ef409f562febdd1cCalifornia State AGfiled 2013-12-29(17d gap)Candidate
- bd_cf15287f960706e9California State AGfiled 2014-01-16(35d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-43483
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 12, 2013
- Raw hash
- 5b77a38f4351d8001efb6feee947a245cbe8ff95016e91cbed223c03dc16d965
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Victim entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Dec 12, 2013
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.