AMERICAN EXPRESS COMPANY
ent_019ecb3afeb7489074f10bbbcaf73d25
Disclosures
3
State AG · 1 jurisdiction
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
—
no filed count in sample
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- AMERICAN EXPRESS COMPANY
- Normalized
- american express— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- R4PP93JZOLY261QX3811
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- americanexpress.com
Disclosure history (3)newest first
- 🐻California State AGas reporting2016-02-23
American Express (AXP) filed a California SB-24 breach notification regarding a data incident where law enforcement recovered illegally obtained card member account information. AXP stated its systems were not directly compromised, but card numbers, names, and expiration dates for some members were among the recovered data. AXP is monitoring accounts for fraud and notifying affected cardholders as a precaution.
- 🐻California State AGas reporting2016-02-22
American Express (AXP) filed a California SB 24 breach notification regarding illegally obtained card member account information recovered by law enforcement. AXP stated its systems were not compromised, but card numbers, names, and expiration dates may have been exposed. Customers are advised to monitor accounts for fraud.
- 🐻California State AGas reporting2014-09-24
American Express (AXP) notified California residents that their card information (name, account number, expiration date, effective date) was recovered during a law enforcement investigation. SSN was not impacted. No unauthorized activity was detected. AXP placed additional fraud monitoring on affected accounts.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of AMERICAN EXPRESS COMPANY — not by AMERICAN EXPRESS COMPANY itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 🐻California State AGvia American Express National Bank2025-04-23
American Express National Bank disclosed that on February 19, 2025, some personal information related to High Yield Savings Account customers was inadvertently disclosed to an unauthorized third party. The bank is monitoring accounts for fraud and offering two years of complimentary Experian IdentityWorks identity theft protection.
- 🐻California State AGvia AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.2022-11-18
American Express Travel Related Services Company notified customers that a third-party service provider suffered a cyber attack on July 26, 2022, potentially impacting customer information. American Express confirmed on November 3, 2022, that some customer data was involved. The company is monitoring accounts for fraud and offering two years of complimentary Experian IdentityWorks identity theft protection. No specific data types or affected counts were disclosed in the sample letter.
- 🦞Maine State AGvia AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.2022-11-18
American Express Travel Related Services Company reported a data breach affecting 52 Maine residents. The breach, which was discovered on July 26, 2022, involved an external system hack. The compromised information includes names and driver's license or non-driver identification card numbers. The company offered 24 months of identity theft protection services through Experian.
- 🦬Montana State AGvia AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.2020-06-30
American Express Travel Related Services Company reported a data breach to the Montana Attorney General. The breach was reported on 2020-06-30. The breach occurred from 4/16/2020 to 4/18/2020. 3 Montana residents were affected.
- 🦬Montana State AGvia AMERICAN EXPRESS LIMITED2019-09-30
American Express reported a data breach to the Montana Attorney General. The breach was reported on 2019-09-30. The breach occurred from 8/28/2019 to 9/11/2019. 2 Montana residents were affected.
- 🐻California State AGvia AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.2018-08-02
American Express Travel Related Services Company, Inc. disclosed a data breach involving its third-party vendor, Expedia, affecting the Orbitz travel booking platform. The incident, occurring between July 5 and July 9, 2018, exposed customer names, payment card information, email, and physical/billing addresses. American Express notified affected individuals on July 31, 2018, offering two years of Experian IdentityWorks. The attack targeted the vendor's platform, not American Express's core systems.
- 🐻California State AGvia AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.2016-03-10
American Express notified California residents that a data security incident occurred at a merchant where they used their cards. Account information, including card numbers, names, and expiration dates, may have been compromised. American Express systems were not directly breached; the incident involved a third-party merchant. The breach date is listed as December 7, 2013. American Express is monitoring accounts for fraud.
- 🐻California State AGvia AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.2016-01-28
American Express notified California residents that a data security incident occurred at a third-party merchant where they used their cards. The incident, dated June 2, 2014, potentially compromised card account numbers, names, and expiration dates. American Express systems were not compromised. The company is monitoring accounts for fraud and advised customers to review statements.
- 🐻California State AGvia AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.2016-01-27
American Express notified California residents that a third-party service provider used by merchants experienced unauthorized access. Card account numbers, names, and expiration dates may have been compromised. American Express systems were not directly breached. The company is monitoring accounts for fraud.
- 🐻California State AGvia AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.2016-01-26
American Express notified customers that a third-party service provider used by merchants experienced unauthorized access. Card account numbers, names, and expiration dates may have been compromised. American Express systems were not directly breached. The incident occurred on November 20, 2014. American Express is monitoring accounts for fraud.