HackingVulnerability ExploitCustomer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
American Express Travel Related Services Company, Inc. and/or its Affiliates
bd_e23027a6db534655 · schema v1 · pii pii-v1
Full breach record for American Express Travel Related Services Company, Inc. and/or its Affiliates →American Express notified customers that a merchant, Tennis Express, detected unauthorized access to its website files on December 19, 2012. The breach exposed American Express card account numbers, names, and expiration dates. Social Security numbers were not impacted. American Express placed additional fraud monitoring on affected cards and offered identity theft assistance.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_db62fa20db2e76acCalifornia State AGfiled 2013-04-04(9d gap)Candidate
- bd_109d68ce96252abdCalifornia State AGfiled 2013-02-19(35d gap)Candidate
- bd_37cf6b069cfc1f5dCalifornia State AGfiled 2013-05-02(37d gap)Candidate
- bd_8f2c57dc544bccd9California State AGfiled 2013-05-13(48d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 74d gap
- bd_2f0d53851a644835California State AGfiled 2013-01-11(74d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-40876
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 26, 2013
- Raw hash
- 488cfa3b7a28d83709aeabcb7056a5e68b7080de3fdb91395d40f5134043a54a
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Victim entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Third party
- via Tennis Express
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.