HackingFinancial ServicesFinanceVulnerability ExploitCapture Stored DataSupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
American Express Travel Related Services Company, Inc. and/or its Affiliates
bd_3340c9b0b589356b · schema v1 · pii pii-v1
Full breach record for American Express Travel Related Services Company, Inc. and/or its Affiliates →A merchant where American Express cardmembers used their cards detected unauthorized access to the merchant's website. The breach exposed cardmember account numbers, names, and card expiration dates. American Express placed additional fraud monitoring on affected accounts and notified cardmembers in August 2012. The breach date recorded is April 2, 2012. Social Security numbers were not affected.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_a8059ebf4d1ae735California State AGfiled 2012-08-14(8d gap)Candidate
- bd_fd8a3e0ef562cc32California State AGfiled 2012-09-03(12d gap)Candidate
- bd_a94fc90d17729792California State AGfiled 2012-09-11(20d gap)Candidate
- bd_bbced53d8ee975a3California State AGfiled 2012-07-17(36d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 90d gap
- bd_85d408cdae691b48California State AGfiled 2012-11-06(76d gap)Candidate
- bd_56bc41129eccb17aCalifornia State AGfiled 2012-11-20(90d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-32581
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 22, 2012
- Raw hash
- 38df3a380b98ad9e3d14b3f21db39005c4b4f86832dc56558b8aef68facc86ef
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Victim entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
- Industry
- Financial Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Aug 22, 2012
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1530 Data from Cloud Storage Object
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.