AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.
ent_019e2413a3a3659f49460901400ef7cd
Disclosures
13
State AG · 3 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
52
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.
- Normalized
- american express travel related— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- SV60HQBVB2DXO09D8H53
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- AMERICAN EXPRESS COMPANY— per GLEIF relationship records
Disclosure history (13)newest first
- 🐻California State AGas victim2022-11-18
American Express Travel Related Services Company notified customers that a third-party service provider suffered a cyber attack on July 26, 2022, potentially impacting customer information. American Express confirmed on November 3, 2022, that some customer data was involved. The company is monitoring accounts for fraud and offering two years of complimentary Experian IdentityWorks identity theft protection. No specific data types or affected counts were disclosed in the sample letter.
- 🦞Maine State AGas victim2022-11-18
American Express Travel Related Services Company reported a data breach affecting 52 Maine residents. The breach, which was discovered on July 26, 2022, involved an external system hack. The compromised information includes names and driver's license or non-driver identification card numbers. The company offered 24 months of identity theft protection services through Experian.
- 🦬Montana State AGas victim2020-06-30
American Express Travel Related Services Company reported a data breach to the Montana Attorney General. The breach was reported on 2020-06-30. The breach occurred from 4/16/2020 to 4/18/2020. 3 Montana residents were affected.
- 🐻California State AGas victim2018-08-02
American Express Travel Related Services Company, Inc. disclosed a data breach involving its third-party vendor, Expedia, affecting the Orbitz travel booking platform. The incident, occurring between July 5 and July 9, 2018, exposed customer names, payment card information, email, and physical/billing addresses. American Express notified affected individuals on July 31, 2018, offering two years of Experian IdentityWorks. The attack targeted the vendor's platform, not American Express's core systems.
- 🐻California State AGas reporting2018-03-22
American Express Travel Related Services Company, Inc. reported a data breach involving its third-party vendor, Orbitz. The incident affected the Orbitz booking platform, impacting transactions from January 1, 2016, through December 22, 2017. The breach exposed customer personal information, including names, payment card details, dates of birth, phone numbers, email addresses, and physical/billing addresses. American Express notified affected individuals, offering two years of Experian IdentityWorks and fraud monitoring. The Orbitz platform has been remediated.
- 🐻California State AGas victim2016-03-10
American Express notified California residents that a data security incident occurred at a merchant where they used their cards. Account information, including card numbers, names, and expiration dates, may have been compromised. American Express systems were not directly breached; the incident involved a third-party merchant. The breach date is listed as December 7, 2013. American Express is monitoring accounts for fraud.
- 🐻California State AGas victim2016-01-28
American Express notified California residents that a data security incident occurred at a third-party merchant where they used their cards. The incident, dated June 2, 2014, potentially compromised card account numbers, names, and expiration dates. American Express systems were not compromised. The company is monitoring accounts for fraud and advised customers to review statements.
- 🐻California State AGas victim2016-01-27
American Express notified California residents that a third-party service provider used by merchants experienced unauthorized access. Card account numbers, names, and expiration dates may have been compromised. American Express systems were not directly breached. The company is monitoring accounts for fraud.
- 🐻California State AGas victim2016-01-26
American Express notified customers that a third-party service provider used by merchants experienced unauthorized access. Card account numbers, names, and expiration dates may have been compromised. American Express systems were not directly breached. The incident occurred on November 20, 2014. American Express is monitoring accounts for fraud.
- 🐻California State AGas victim2016-01-08
American Express notified customers that a third-party service provider engaged by merchants experienced unauthorized access. American Express systems were not compromised, but customer name, address, card number, expiration date, and security code may have been involved. The breach date is listed as December 21, 2014.
- 🐻California State AGas victim2014-05-29
American Express notified California residents that their card account numbers, expiration dates, effective dates, and four-digit front-of-card codes were recovered during a law enforcement and/or American Express investigation. The company stated that Social Security numbers were not impacted and no unauthorized activity was detected. Additional fraud monitoring was placed on affected cards.
- 🐻California State AGas victim2012-12-12
American Express notified California cardholders that a third-party merchant's website suffered unauthorized access, exposing American Express card account numbers, cardholder names, and card expiration dates. Social Security numbers were not impacted. The breach occurred around November 1, 2010. American Express placed additional fraud monitoring on affected accounts and provided identity theft assistance resources.
- 🐻California State AGas victim2012-09-13
American Express notified customers that a merchant where they used their cards detected unauthorized access to its data files on April 2, 2012. The affected data included American Express Card account numbers, names, and expiration dates. Social Security numbers were not impacted. American Express placed additional fraud monitoring on affected cards and reminded customers they are not liable for fraudulent charges.
Subsidiary disclosures (2)filed by group companies
◈ These filings were made by or about subsidiaries of AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC. — not by AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 🐻California State AGvia American Express National Bank2025-04-23
American Express National Bank disclosed that on February 19, 2025, some personal information related to High Yield Savings Account customers was inadvertently disclosed to an unauthorized third party. The bank is monitoring accounts for fraud and offering two years of complimentary Experian IdentityWorks identity theft protection.
- 🦬Montana State AGvia AMERICAN EXPRESS LIMITED2019-09-30
American Express reported a data breach to the Montana Attorney General. The breach was reported on 2019-09-30. The breach occurred from 8/28/2019 to 9/11/2019. 2 Montana residents were affected.