HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowActive
American Express Travel Related Services Company, Inc. and/or its Affiliates
bd_a908e05d43a082c7 · schema v1 · pii pii-v1
Full breach record for American Express Travel Related Services Company, Inc. and/or its Affiliates →California AG SB24-44555: American Express notified cardholders that a merchant's data files were accessed, exposing card account numbers, names, and expiration dates. No SSN or unauthorized activity was detected. American Express placed additional fraud monitoring and offered Identity Theft Assistance.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_857ea071b1281eb6California State AGfiled 2014-04-01(7d gap)Candidate
- bd_efebb1bd4f43777cCalifornia State AGfiled 2014-04-07(13d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-44555
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 25, 2014
- Raw hash
- 57d752f35750b77250a622e0b0fb990880ba5529a936592978322c36ae00f82c
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
- Industry
- financial_services
Victim entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
- Industry
- financial_services
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jul 19, 2024
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.