HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
American Express Travel Related Services Company, Inc. and/or its Affiliates
bd_fd8a3e0ef562cc32 · schema v1 · pii pii-v1
Full breach record for American Express Travel Related Services Company, Inc. and/or its Affiliates →American Express notified cardholders that a merchant where they used their cards detected unauthorized access to its data files. The affected data included American Express Card account numbers, names, and expiration dates. Social Security numbers were not impacted. American Express placed additional fraud monitoring on affected cards and stated it does not hold cardholders liable for fraudulent charges. The breach date is listed as April 2, 2012.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_a94fc90d17729792California State AGfiled 2012-09-11(8d gap)Candidate
- bd_3340c9b0b589356bCalifornia State AGfiled 2012-08-22(12d gap)Candidate
- bd_a8059ebf4d1ae735California State AGfiled 2012-08-14(20d gap)Candidate
- bd_bbced53d8ee975a3California State AGfiled 2012-07-17(48d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 78d gap
- bd_85d408cdae691b48California State AGfiled 2012-11-06(64d gap)Candidate
- bd_56bc41129eccb17aCalifornia State AGfiled 2012-11-20(78d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-36351
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 3, 2012
- Raw hash
- 59f4deb674e1a0bc0756e28dc2fa5e285bdd6f88c36f98c4280b3f19ac3d324e
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Victim entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Third party
- via merchant
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.