HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedPIIFINANCIAL_ACCOUNTLowContained
American Express Travel Related Services Company, Inc. and/or its Affiliates
bd_a94fc90d17729792 · schema v1 · pii pii-v1
Full breach record for American Express Travel Related Services Company, Inc. and/or its Affiliates →American Express (AXP) notified California AG regarding a breach on 2012-07-19 involving unauthorized access to a merchant's data files. The incident exposed card account numbers, cardholder names, and expiration dates. AXP implemented additional fraud monitoring and offered Identity Theft Assistance to affected cardholders.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_fd8a3e0ef562cc32California State AGfiled 2012-09-03(8d gap)Candidate
- bd_3340c9b0b589356bCalifornia State AGfiled 2012-08-22(20d gap)Candidate
- bd_a8059ebf4d1ae735California State AGfiled 2012-08-14(28d gap)Candidate
- bd_85d408cdae691b48California State AGfiled 2012-11-06(56d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 70d gap
- bd_bbced53d8ee975a3California State AGfiled 2012-07-17(56d gap)Candidate
- bd_56bc41129eccb17aCalifornia State AGfiled 2012-11-20(70d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-36427
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 11, 2012
- Raw hash
- c5aff37c938de4237f7d1859e355b64d52797999f2ed7c7c8eec9b6667eb6992
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Victim entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Incident
- Discovered
- Jul 19, 2012
- Materiality determined
- Jul 19, 2012
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- Partner
- Initial access
- supply_chain
Compliance
- Time to disclose
- 8 weeks(54 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.