HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowActive
American Express Travel Related Services Company, Inc. and/or its Affiliates
bd_ff2918b090b2e886 · schema v1 · pii pii-v1
Full breach record for American Express Travel Related Services Company, Inc. and/or its Affiliates →American Express (AXP) notified California residents that a merchant where they used their Amex card experienced unauthorized access to data files. The merchant's files included card account numbers, names, and expiration dates. SSN was not impacted. AXP placed additional fraud monitoring on affected cards and advised cardholders to review statements, sign up for alerts, and monitor credit reports.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_1e8be6fbdd7ab56fCalifornia State AGfiled 2015-05-01(26d gap)Candidate
- bd_b8c1f25ca790adc0California State AGfiled 2015-04-30(27d gap)Candidate
- bd_92b4536bf4808f8bCalifornia State AGfiled 2015-07-24(58d gap)Candidate
- bd_aa75eec10a9f8531California State AGfiled 2015-07-27(61d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 104d gap
- bd_265ab689b6b95c1eCalifornia State AGfiled 2015-08-28(93d gap)Candidate
- bd_6c67934ec48b58ecCalifornia State AGfiled 2015-09-08(104d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-56134
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 27, 2015
- Raw hash
- 49d288764c446264e678ff02b30c4cf1a3a68b9c65de74e46b42cda880bf0baf
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Victim entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.