HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
American Express Travel Related Services Company, Inc. and/or its Affiliates
bd_e8340b0b182201be · schema v1 · pii pii-v1
Full breach record for American Express Travel Related Services Company, Inc. and/or its Affiliates →American Express Travel Related Services Company, Inc. reported a data security breach to the California Office of the Attorney General (SB 24). The incident involved the recovery of American Express Card account numbers, expiration dates, and effective dates by law enforcement and/or American Express. Social Security numbers were not impacted, and no unauthorized activity was detected on card accounts. The company implemented additional fraud monitoring and notified affected cardholders via letter.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_402a2f5e74c846a3California State AGfiled 2015-04-01(34d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-55813
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 5, 2015
- Raw hash
- 1ab16c3eee1b322bad172cda47dc5d123bf36ae300b7f4c8e31593bb1935ce09
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
- Industry
- financial_services
Victim entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
- Industry
- financial_services
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted Breach Notification to California Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.