HackingSupply Chain (3P Vendor)Customer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
American Express Travel Related Services Company, Inc. and/or its Affiliates
bd_6c67934ec48b58ec · schema v1 · pii pii-v1
Full breach record for American Express Travel Related Services Company, Inc. and/or its Affiliates →American Express notified customers that a merchant where they used their card detected unauthorized access to its data files on December 30, 2014. The affected data included card account numbers, names, and expiration dates. Social Security numbers were not impacted. American Express placed additional fraud monitoring on affected cards and stated customers are not liable for fraudulent charges.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_265ab689b6b95c1eCalifornia State AGfiled 2015-08-28(11d gap)Candidate
- bd_aa75eec10a9f8531California State AGfiled 2015-07-27(43d gap)Candidate
- bd_92b4536bf4808f8bCalifornia State AGfiled 2015-07-24(46d gap)Candidate
- bd_ff2918b090b2e886California State AGfiled 2015-05-27(104d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 131d gap
- bd_1e8be6fbdd7ab56fCalifornia State AGfiled 2015-05-01(130d gap)Candidate
- bd_b8c1f25ca790adc0California State AGfiled 2015-04-30(131d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-57712
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 8, 2015
- Raw hash
- 8d2e6dfa49d9751c40e18162d2b72aa7122cad53399e66e368666dd97cf231e4
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Victim entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- Threat actor
- External
- Third party
- via merchant
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.