HackingSupply Chain (3P Vendor)Customer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.
bd_7da5fb7554b9d004 · schema v1 · pii pii-v1
Full breach record for AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC. →American Express notified California residents that a data security incident occurred at a merchant where they used their cards. Account information, including card numbers, names, and expiration dates, may have been compromised. American Express systems were not directly breached; the incident involved a third-party merchant. The breach date is listed as December 7, 2013. American Express is monitoring accounts for fraud.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-60413
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 10, 2016
- Raw hash
- 7d2b90f9c060188e2d23af8d2b034a8b128215b6f85309f97c31308d94c4a1e8
Reporting entity
- Name
- AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.norm: american express travel related
Victim entity
- Name
- AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.norm: american express travel related
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via merchant
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.