HackingVulnerability ExploitCustomer Data InvolvedSupply Chain (3P Vendor)FINANCIAL_ACCOUNTIDENTITY_BASICLowContained
American Express Travel Related Services Company, Inc. and/or its Affiliates
bd_9a741bbe562f8449 · schema v1 · pii pii-v1
Full breach record for American Express Travel Related Services Company, Inc. and/or its Affiliates →American Express notified customers that a merchant where they used their cards detected unauthorized access to website files on February 15, 2011. Affected data included card account numbers, names, and expiration dates. Social Security numbers were not impacted. American Express placed additional fraud monitoring on affected accounts.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-57108
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 21, 2015
- Raw hash
- 8c7f612ef3f166d2ea2604c3fd04dd7b1f28d044c11ce4713ab29d9132f798d2
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Victim entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Third party
- via Merchant
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.