HackingVulnerability ExploitCustomer Data InvolvedSupply Chain (3P Vendor)PCIFINANCIAL_ACCOUNTIDENTITY_BASICLowResolved
American Express Travel Related Services Company, Inc. and/or its Affiliates
bd_e289da0654eb6b31 · schema v1 · pii pii-v1
Full breach record for American Express Travel Related Services Company, Inc. and/or its Affiliates →American Express notified California residents that a merchant where they used their card detected unauthorized access to website files on June 13, 2012. Affected data included card account numbers, names, and expiration dates. Social Security numbers were not impacted. American Express placed additional fraud monitoring on affected cards and offered identity theft assistance.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_71fb800686d8b0caCalifornia State AGfiled 2014-06-16(14d gap)Candidate
- bd_c677bf3ccf71758fCalifornia State AGfiled 2014-06-17(15d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-45289
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 2, 2014
- Raw hash
- 522ee17067369a413e4a432fa4bd0e60e5adaf02506011a62781d1f8f3601db9
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Victim entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jun 2, 2014
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Third party
- via merchant
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.