HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowActive
American Express Travel Related Services Company, Inc. and/or its Affiliates
bd_6db126407d0eeaa8 · schema v1 · pii pii-v1
Full breach record for American Express Travel Related Services Company, Inc. and/or its Affiliates →American Express Travel Related Services Company, Inc. reported a data breach involving a third-party payment processor. Unauthorized access to the processor's system resulted in the potential exposure of cardholder names, addresses, account numbers, expiration dates, and dates of birth. Social Security numbers were not impacted. The incident is classified as a third-party supply chain compromise involving credential misuse. American Express has implemented additional fraud monitoring and is working with the processor to assess the scope.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-57120
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 22, 2015
- Raw hash
- 09578cbd7c430a645a9213e5f0772e3ab19800cad3904edb291a63672321d474
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Victim entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Submitted Breach Notification to California Office of the Attorney General
- Third party
- via Payment Processor
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.