HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowActive
American Express Travel Related Services Company, Inc. and/or its Affiliates
bd_38c3d77c02927712 · schema v1 · pii pii-v1
Full breach record for American Express Travel Related Services Company, Inc. and/or its Affiliates →American Express (AXP) filed a California SB-24 breach notification regarding a data incident where law enforcement recovered illegally obtained card member account information. AXP stated its systems were not directly compromised, but card numbers, names, and expiration dates for some members were among the recovered data. AXP is monitoring accounts for fraud and notifying affected cardholders as a precaution.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_8175faa42a0fafe4California State AGfiled 2016-02-22(1d gap)Candidate
- bd_e24ef213d8083b75California State AGfiled 2016-01-07(47d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-60171
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 23, 2016
- Raw hash
- 78fa169a406d75ebdb8934850f05a42387bcf9d0e95f25531f49a042941384b2
Reporting entity
- Name
- AMERICAN EXPRESS COMPANYnorm: american express
- Domain
- americanexpress.com
Victim entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Law enforcement officials recovered illegally obtained personal and account information
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.