AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.
bd_73f028e269ca8c3a · schema v1 · pii pii-v1
Full breach record for AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC. →443 incidents on fileOrbitz, a third-party vendor for American Express Travel, suffered a cyber attack affecting transactions from Jan 1, 2016 to Dec 22, 2017. American Express notified cardholders on March 16, 2018. Affected data includes names, payment card info, DOB, phone, email, address, and gender. SSNs and passport info were not involved. American Express offered 2 years of Experian IdentityWorks.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 1, 2016
Begins
Mar 16, 2018
Discovered
Mar 22, 2018
Filed
vs. sector median
12 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Washington State AGbd_0ac803c23242c05f2018-03-22Verified
- Massachusetts State AGbd_56a5f7843c5167a12018-03-21 · +1dVerified
- Massachusetts State AGbd_a0c510dbbe6ad7ed2018-05-02 · +41dCandidate
- Massachusetts State AGbd_7454f265dc34e7502018-05-23 · +62dCandidate
Show 1 more filing ↓Show fewer ↑up to 97d gap
- Massachusetts State AGbd_fe4f7cdf80fdfc2d2018-06-27 · +97dCandidate
Filing propagation · 6 filings · 3 states
View merged incident ↗Pattern: first filing Mar 21 (MA), last Jun 27 (MA) — a 98-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.