HackingSupply Chain (3P Vendor)Customer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.
bd_6a077442be4fd9d6 · schema v1 · pii pii-v1
Full breach record for AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC. →American Express Travel Related Services Company notified customers that a third-party service provider suffered a cyber attack on July 26, 2022, potentially impacting customer information. American Express confirmed on November 3, 2022, that some customer data was involved. The company is monitoring accounts for fraud and offering two years of complimentary Experian IdentityWorks identity theft protection. No specific data types or affected counts were disclosed in the sample letter.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_7e47082c9bf03a69Maine State AGfiled 2022-11-18Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-559336
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 18, 2022
- Raw hash
- 4ac394159cba5d3e292d876642b97467b6e8d3a538d6acd8f787f2cf579c16d2
Reporting entity
- Name
- AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.norm: american express travel related
Victim entity
- Name
- AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.norm: american express travel related
Incident
- Discovered
- Jul 26, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- Threat actor
- External
Compliance
- Time to disclose
- 16 weeks(115 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.