HackingStolen CredentialsCustomer Data InvolvedSupply Chain (3P Vendor)PCIFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
American Express Travel Related Services Company, Inc. and/or its Affiliates
bd_a8059ebf4d1ae735 · schema v1 · pii pii-v1
Full breach record for American Express Travel Related Services Company, Inc. and/or its Affiliates →American Express notified California residents that a merchant, Creative Croissants - LAX, detected unauthorized access to its data files on March 2, 2012. The breach potentially exposed American Express card account numbers, names, and expiration dates. American Express placed additional fraud monitoring on affected cards and advised customers to review statements. No Social Security numbers were impacted.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_3340c9b0b589356bCalifornia State AGfiled 2012-08-22(8d gap)Candidate
- bd_fd8a3e0ef562cc32California State AGfiled 2012-09-03(20d gap)Candidate
- bd_a94fc90d17729792California State AGfiled 2012-09-11(28d gap)Candidate
- bd_bbced53d8ee975a3California State AGfiled 2012-07-17(28d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 98d gap
- bd_85d408cdae691b48California State AGfiled 2012-11-06(84d gap)Candidate
- bd_56bc41129eccb17aCalifornia State AGfiled 2012-11-20(98d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-32467
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 14, 2012
- Raw hash
- 268a9f924afcf68a127c83f1fedfb2843aab4167109eca59bbdb386a842a3664
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Victim entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
- Industry
- retail_consumer
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Aug 14, 2012
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Filed breach notification with California Attorney General
- Third party
- via Creative Croissants - LAX
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.