HackingFinancial ServicesFinanceVulnerability ExploitCapture Stored DataSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPCIFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.
bd_92f07ec4a8da0fb9 · schema v1 · pii pii-v1
Full breach record for AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC. →American Express notified California cardholders that a third-party merchant's website suffered unauthorized access, exposing American Express card account numbers, cardholder names, and card expiration dates. Social Security numbers were not impacted. The breach occurred around November 1, 2010. American Express placed additional fraud monitoring on affected accounts and provided identity theft assistance resources.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-37221
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 12, 2012
- Raw hash
- 929dd4bf8876c287fdb65696c99d04e05da732df884b0d0fbdb070e3aca0454e
Reporting entity
- Name
- AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.norm: american express travel related
Victim entity
- Name
- AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.norm: american express travel related
- Industry
- Financial Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1530 Data from Cloud Storage Object
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.