HackingCustomer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
American Express Travel Related Services Company, Inc. and/or its Affiliates
bd_2f0d53851a644835 · schema v1 · pii pii-v1
Full breach record for American Express Travel Related Services Company, Inc. and/or its Affiliates →American Express notified cardholders that a merchant where they used their cards experienced unauthorized access to data files on September 1, 2012. Affected data included card account numbers, names, and expiration dates. Social Security numbers were not impacted. American Express placed additional fraud monitoring on affected accounts.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_109d68ce96252abdCalifornia State AGfiled 2013-02-19(39d gap)Candidate
- bd_e23027a6db534655California State AGfiled 2013-03-26(74d gap)Candidate
- bd_db62fa20db2e76acCalifornia State AGfiled 2013-04-04(83d gap)Candidate
- bd_37cf6b069cfc1f5dCalifornia State AGfiled 2013-05-02(111d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 122d gap
- bd_8f2c57dc544bccd9California State AGfiled 2013-05-13(122d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-38599
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 11, 2013
- Raw hash
- b903a3d2c21db300198072005b658e722636b74f0456eb5d6ac8f3723526be06
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Victim entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jan 11, 2013
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unknown
- Threat actor
- External
- Third party
- via A merchant where you used your American Express Card
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.