Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
State AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedmoderate sensitivity
Affected (total reported)
—
Data types
2
Identity (basic) · Financial account
Jurisdictions
1
CA
Linked filings
4
all State AG
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
Breach window
Dec 21, 2014
When the intrusion reportedly occurred, per the linked filings
383 days
4 State AG filingsJan 8, 2016 – Jan 28, 2016ExpandCollapse
American Express notified customers that a third-party service provider engaged by merchants experienced unauthorized access. American Express systems were not compromised, but customer name, address, card number, expiration date, and security code may have been involved. The breach date is listed as December 21, 2014.
American Express notified customers that a third-party service provider used by merchants experienced unauthorized access. Card account numbers, names, and expiration dates may have been compromised. American Express systems were not directly breached. The incident occurred on November 20, 2014. American Express is monitoring accounts for fraud.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
American Express notified California residents that a third-party service provider used by merchants experienced unauthorized access. Card account numbers, names, and expiration dates may have been compromised. American Express systems were not directly breached. The company is monitoring accounts for fraud.
American Express notified California residents that a data security incident occurred at a third-party merchant where they used their cards. The incident, dated June 2, 2014, potentially compromised card account numbers, names, and expiration dates. American Express systems were not compromised. The company is monitoring accounts for fraud and advised customers to review statements.