HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowActive
American Express Travel Related Services Company, Inc. and/or its Affiliates
bd_265ab689b6b95c1e · schema v1 · pii pii-v1
Full breach record for American Express Travel Related Services Company, Inc. and/or its Affiliates →American Express Travel Related Services Company, Inc. reported a data breach involving a third-party merchant. The merchant's data files were compromised, exposing American Express card account numbers, cardholder names, and expiration dates. Social Security numbers were not impacted, and no unauthorized activity was detected on card accounts. The company placed additional fraud monitoring on affected cards and notified cardholders via letter, advising them to review statements and credit reports.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_6c67934ec48b58ecCalifornia State AGfiled 2015-09-08(11d gap)Candidate
- bd_aa75eec10a9f8531California State AGfiled 2015-07-27(32d gap)Candidate
- bd_92b4536bf4808f8bCalifornia State AGfiled 2015-07-24(35d gap)Candidate
- bd_ff2918b090b2e886California State AGfiled 2015-05-27(93d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 120d gap
- bd_1e8be6fbdd7ab56fCalifornia State AGfiled 2015-05-01(119d gap)Candidate
- bd_b8c1f25ca790adc0California State AGfiled 2015-04-30(120d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-57613
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 28, 2015
- Raw hash
- 572da5026405b0608dc4cb996540675ad1b230e7b9381bdf4751faa0ab1b4bd6
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
- Industry
- financial_services
Victim entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
- Industry
- financial_services
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- PartnerFinancial
- Regulator citations
- Submitted Breach Notification to California Office of the Attorney General
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.