Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
American Express

American Express Vendor Cyber Rating & Cyber Score

americanexpress.com

At American Express, we know that with the right backing, people and businesses have the power to progress in incredible ways. Whether we’re supporting our customers’ financial confidence to move ahead, taking commerce to new heights, or encouraging people to explore the world, our colleagues are constantly striving to uphold our powerful backing promise to our customers and each other every day. These beliefs have been our North Star for 170 years as our business transformed – from helping evacuate travelers during World Wars, to ensuring the safety of our customers’ funds during the Great Depression in the U.S., to creating the Shop Small® movement to help small businesses recover from the Financial Crisis, to providing aid to


American Express A.I CyberSecurity Scoring

American Express
Company Information
Website:https://www.americanexpress.com/
Employees number:80,900
Number of followers:3,251,004
NAICS:52
Industry Type:Financial Services
Homepage:americanexpress.com
American Express Risk Score (AI oriented)
Between 700 and 749
logo
American ExpressFinancial Services
Updated:
07/05/2026
710/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
American Express Global Score (TPRM)
xxxx
logo
American ExpressFinancial Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

American Express
American ExpressModerate
Current Score
710Ba (MODERATE)
01000
50 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
715Before Incident
MAY 2026
709Before Incident
APRIL 2026
709Before Incident
MARCH 2026
707Before Incident
FEBRUARY 2026
704Before Incident
JANUARY 2026
702Before Incident
DECEMBER 2025
706Before Incident
NOVEMBER 2025
697Before Incident
OCTOBER 2025
694Before Incident
SEPTEMBER 2025
691Before Incident
AUGUST 2025
688Before Incident
JULY 2025
685Before Incident
FEBRUARY 2025
698Before Incident
Breach
19 Feb 2025American Express
American Express National Bank

American Express National Bank Data Breach - February 2025

666After Incident
CRITICAL-32
AME038090625
American Express National Bank experienced a data breach on February 19, 2025, resulting in the inadvertent exposure of personal information to an unauthorized third party. While the exact nature of the compromised data remains undisclosed, the incident suggests a failure in security protocols that allowed sensitive customer or employee information to be accessed without authorization. Such breaches typically raise concerns over identity theft, financial fraud, or reputational damage, depending on the scope of the exposed data. The lack of clarity on the specific types of information leaked (e.g., financial records, personally identifiable information, or internal documents) complicates risk assessment, but the breach inherently signals operational vulnerabilities within the bank’s cybersecurity framework. Customers may face heightened scrutiny over potential misuse of their data, while the bank could encounter regulatory penalties, loss of trust, and financial liabilities tied to remediation efforts. The incident underscores the critical need for robust data protection measures, particularly in financial institutions handling high volumes of sensitive transactions.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Unknown (personal information)Identity Theft Risk: Potential (due to personal information exposure)
DATA BREACH
Type Of Data Compromised: Personal information (specific types unknown)Data Exfiltration: Yes (inadvertent disclosure to unauthorized third party)Personally Identifiable Information: Yes (unspecified)
JULY 2022
595Before Incident
Cyber Attack
26 Jul 2022American Express
American Express Travel Related Services Company

American Express Travel Related Services Company Data Breach

585After Incident
CRITICAL-10
AME345072725
The California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company on November 18, 2022. The breach occurred on July 26, 2022, when a third-party service provider was victimized by a cyber attack, potentially impacting customer information, though specific details about the compromised data are unknown.
INCIDENT DETAILS -
TYPE
Data Breach
JANUARY 2021
526Before Incident
Breach
01 Jan 2021American Express
American Express

American Express Data Leak

491After Incident
CRITICAL-35
AME234915422
An unknown hacker leaked the personal data of about 10,000 American Express credit cardholders. The leaked data include account numbers, names, full addresses, phone numbers, date of birth, gender, and other personally identifiable information. Amex immediately took action and alerted the affected customers to be alerted for any fraudulent activities.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Account numbersNamesFull addressesPhone numbersDate of birthGender
DATA BREACH
Personal InformationNumber Of Records Exposed: 10,000Sensitivity Of Data: HighAccount numbersNamesFull addressesPhone numbersDate of birthGender
JULY 2020
521Before Incident
Breach
07 Jul 2020American Express
American Express Travel Related Services Company, Inc.

American Express Travel Related Services Company, Inc. Data Breach

489After Incident
MEDIUM-32
AME637071625
The data breach reported by the Massachusetts Office of Consumer Affairs and Business Regulation on July 7, 2020, involved American Express Travel Related Services Company, Inc. The breach affected 1 resident and included compromised electronic records such as credit and debit numbers. This incident highlights the vulnerability of financial information in electronic systems and the potential risks associated with data breaches.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
credit and debit numbers
DATA BREACH
credit and debit numbersNumber Of Records Exposed: 1
MARCH 2016
100Before Incident
Breach
01 Mar 2016American Express
American Express

American Express Data Breach

100After Incident
CRITICAL0
AME1751261023
American Express is alerting customers to the possibility that a security compromise at a third-party service provider has exposed their payment card information. American Express claims that hackers may have taken data connected to cards that were issued in the past or are now in use. Account numbers, names, and expiration dates are among the pieces of information that were obtained by unauthorised individuals. The business clarifies that this event did not affect any systems owned or controlled by American Express, and that this alert is being sent merely as a precaution. American Express emphasised that the incident had no effect on its financial systems and that it continues to monitor fraudulent activity that could potentially harm cardholders in order to prevent exploitation.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Account numbersNamesExpiration dates
DATA BREACH
Account numbersNamesExpiration datesSensitivity Of Data: High
FEBRUARY 2016
100Before Incident
Breach
23 Feb 2016American Express
American Express Travel Related Services Company, Inc.

American Express Travel Related Services Data Breach

100After Incident
CRITICAL0
AME157072825
The California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc and/or its Affiliates on February 23, 2016. The breach involved illegally obtained personal and account information that may have included Card Members' account numbers and personal details; however, the exact information compromised is currently unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Card Members' account numberspersonal details
DATA BREACH
Card Members' account numberspersonal details
SEPTEMBER 2015
100Before Incident
Breach
23 Sep 2015American Express
American Express Travel Related Services Company, Inc.

American Express Travel Related Services Company Data Breach

100After Incident
MEDIUM0
AME435072425
The California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc on January 26, 2016. The breach occurred on September 23, 2015, affecting certain Card Members' account information, including account numbers and names. The specific number of individuals affected is unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
account numbersnames
DATA BREACH
account numbersnames
AUGUST 2015
100Before Incident
Breach
28 Aug 2015American Express
American Express Company

American Express Travel Related Services Company Data Breach

100After Incident
MEDIUM0
AME120072925
The California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc. on August 28, 2015. The breach involved a merchant theft that potentially exposed American Express Card account numbers, names, and Card information, but did not compromise Social Security numbers.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card account numbersnamesCard information
DATA BREACH
American Express Card account numbersnamesCard information
JULY 2015
100Before Incident
Breach
22 Jul 2015American Express
American Express Company

American Express Travel Related Services Data Breach

100After Incident
MEDIUM0
AME441072725
The California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc. on July 22, 2015. The breach involved unauthorized access to a payment processing system, leading to potential access of account information for some Card Members, including names and addresses, but not Social Security numbers.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
NamesAddressesPayment Processing System
DATA BREACH
NamesAddressesNamesAddresses
APRIL 2015
100Before Incident
Breach
23 Apr 2015American Express
American Express Travel Related Services Company, Inc.

American Express Travel Related Services Data Breach

100After Incident
MEDIUM0
AME824072825
The California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc. on January 27, 2016. The breach occurred on April 23, 2015, due to unauthorized access to a third-party service provider, potentially compromising the account information of some Card Members, including names and card numbers.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Account informationNamesCard numbers
DATA BREACH
Account informationNamesCard numbers
MARCH 2015
100Before Incident
Breach
22 Mar 2015American Express
American Express Travel Related Services Company, Inc.

American Express Data Breach

100After Incident
MEDIUM0
AME701072825
The California Office of the Attorney General reported a data breach on March 22, 2015, affecting American Express Travel Related Services Company, Inc. The breach involved unauthorized access to a third-party service provider's system, compromising Card Members' account information. The incident was reported on January 7, 2016, but the exact number of individuals affected was not disclosed.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Card Members' account information
DATA BREACH
Type Of Data Compromised: Card Members' account information
FEBRUARY 2015
100Before Incident
Breach
01 Feb 2015American Express
American Express Company

American Express Travel Related Services Data Breach

100After Incident
CRITICAL0
AME317072625
The California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc. on July 27, 2015. The breach occurred on February 1, 2015, involving unauthorized access to a payment processing system, potentially affecting account information of Cardmembers, including names and Card account numbers.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
NamesCard account numbersPayment processing system
DATA BREACH
NamesCard account numbers
JANUARY 2015
100Before Incident
Breach
15 Jan 2015American Express
American Express Company

American Express Travel Related Services Company Data Breach

100After Incident
HIGH0
AME949080425
The California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc. on January 15, 2015. Unauthorized access to a merchant's website files potentially affected American Express Card account numbers and other card information, but Social Security numbers were not impacted.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card account numbersother card information
DATA BREACH
American Express Card account numbersother card information
DECEMBER 2014
100Before Incident
Breach
01 Dec 2014American Express
American Express Company

American Express Merchant Data Breach (2014)

100After Incident
HIGH0
AME028091825
In December 2014, the California Office of the Attorney General disclosed a data breach affecting American Express Travel Related Services Company, Inc. The incident involved unauthorized access to a merchant’s data files, potentially exposing American Express Card account numbers and associated card details. While the breach compromised payment-related information, it did not include more sensitive data such as Social Security numbers. The exposure primarily impacted financial transaction data, raising concerns over potential fraudulent activity linked to the compromised card details. Although no evidence of misuse was immediately reported, the breach posed risks to cardholders, including unauthorized transactions or identity fraud attempts tied to the exposed payment information. The incident highlighted vulnerabilities in third-party merchant systems handling American Express card data, prompting notifications to affected individuals and regulatory scrutiny.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card account numbersCard informationIdentity Theft Risk: Low (no Social Security numbers exposed)Payment Information Risk: High (Card account numbers and information exposed)
DATA BREACH
Card account numbersCard informationSensitivity Of Data: High (payment card data)Data Exfiltration: Likely (unauthorized access to merchant's data files)Personally Identifiable Information: No (Social Security numbers not affected)
NOVEMBER 2014
100Before Incident
Breach
01 Nov 2014American Express
American Express Travel Related Services Company, Inc

American Express Data Breach via Third-Party Service Provider

100After Incident
HIGH0
AME001091825
The California Office of the Attorney General disclosed a data breach affecting American Express in January 2016, stemming from an incident in November 2014. The breach involved unauthorized access to a third-party service provider’s system, exposing sensitive customer data. Compromised information included American Express Card account numbers, cardholder names, and other card-related details of certain Card Members. While the exact scale of the breach was not specified, the exposure of financial data posed risks of fraud, identity theft, and reputational harm to affected customers. The incident highlighted vulnerabilities in third-party vendor security, raising concerns about supply chain risks in payment processing ecosystems. American Express likely faced regulatory scrutiny, potential financial liabilities, and erosion of customer trust due to the exposure of payment card information.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card account numbersNamesCard informationThird-party service provider's systemIdentity Theft Risk: PotentialPayment Information Risk: High
DATA BREACH
Payment Card DataPersonally Identifiable Information (PII)Sensitivity Of Data: HighData Exfiltration: PotentialNamesCard account numbers
OCTOBER 2014
107Before Incident
Breach
18 Oct 2014American Express
American Express Company

American Express Travel Related Services Data Breach

100After Incident
CRITICAL-7
AME844072525
The California Office of the Attorney General reported a data breach by American Express Travel Related Services Company, Inc. on January 7, 2016. The breach occurred on October 18, 2014, involving unauthorized access to merchant data files that potentially included customer names, American Express Card account numbers, and expiration dates. The exact number of affected individuals and other specific details are unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Customer namesAmerican Express Card account numbersExpiration dates
DATA BREACH
Customer namesAmerican Express Card account numbersExpiration dates
SEPTEMBER 2014
128Before Incident
Breach
24 Sep 2014American Express
American Express Company

American Express Travel Related Services Company Data Breach

100After Incident
HIGH-28
AME217072625
The California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc. on September 24, 2014. The breach exposed American Express Card information, but it was confirmed that Social Security numbers were not impacted. This incident highlights the vulnerability of financial information in cyber attacks, emphasizing the need for robust security measures to protect sensitive data.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card information
DATA BREACH
Type Of Data Compromised: American Express Card information
AUGUST 2014
148Before Incident
Breach
27 Aug 2014American Express
American Express Company

American Express Travel Related Services Company Data Breach

116After Incident
MEDIUM-32
AME908072625
The California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc. on August 27, 2014. The breach is related to the recovery of American Express Card information, but the exact method of the breach and the number of individuals affected is unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card information
DATA BREACH
American Express Card information
JULY 2014
166Before Incident
Breach
25 Jul 2014American Express
American Express Company

American Express Data Breach

134After Incident
MEDIUM-32
AME528080425
The California Office of the Attorney General reported on July 25, 2014, that American Express Travel Related Services Company, Inc. experienced a data breach wherein American Express Card information, including account numbers and names, was recovered during a law enforcement investigation. The specific date of the breach is not available, and no Social Security numbers were compromised.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card informationaccount numbersnames
DATA BREACH
American Express Card informationaccount numbersnamesnames
JUNE 2014
176Before Incident
Breach
02 Jun 2014American Express
American Express Travel Related Services Company, Inc.

American Express Data Breach

144After Incident
MEDIUM-32
AME443072625
The California Office of the Attorney General reported a data breach at American Express Travel Related Services Company, Inc. on June 2, 2014. The breach, reported on January 28, 2016, potentially compromised account information of an unknown number of Card Members. The compromised data included card numbers, names, and expiration dates. This incident highlights the vulnerability of financial information and the importance of robust cybersecurity measures to protect sensitive data.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
card numbersnamesexpiration dates
DATA BREACH
card numbersnamesexpiration datesNumber Of Records Exposed: unknown
MAY 2014
195Before Incident
Breach
01 May 2014American Express
American Express Company

American Express Data Breach (2014)

163After Incident
HIGH-32
AME041090625
The California Office of the Attorney General disclosed a data breach affecting American Express Travel Related Services Company, Inc. in May 2014. The incident involved the unauthorized exposure of American Express Card account information, specifically card account numbers and expiration dates. However, Social Security numbers remained unaffected, and the exact timeline of the breach, along with the number of impacted individuals, was not publicly disclosed. While the breach did not result in the compromise of highly sensitive personal identifiers (e.g., Social Security numbers), the exposure of payment card details poses risks such as potential fraudulent transactions, phishing attempts, or identity theft targeting cardholders. Financial institutions and affected customers would likely face reputational concerns, increased scrutiny over security protocols, and possible financial losses due to fraudulent activities linked to the exposed data. The breach underscores vulnerabilities in payment system protections, though the absence of broader personal data (e.g., SSNs) limits the severity compared to more extensive leaks.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Card account numberExpiration dateIdentity Theft Risk: Low (no Social Security numbers impacted)Payment Information Risk: High (card account details exposed)
DATA BREACH
Card account numberExpiration dateSensitivity Of Data: High (payment card details)Personally Identifiable Information: No (Social Security numbers not impacted)
APRIL 2014
219Before Incident
Breach
12 Apr 2014American Express
American Express Travel Related Services Company, Inc.

American Express Travel Related Services Data Breach

188After Incident
MEDIUM-31
AME223072725
The California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc. on August 26, 2015. The breach occurred on April 12, 2014, due to unauthorized access to a merchant's website, potentially exposing Cardmembers' American Express Card account numbers, names, and other card information, while Social Security numbers were not affected.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card account numbersnamesother card information
DATA BREACH
American Express Card account numbersnamesother card information
JANUARY 2014
214Before Incident
Breach
07 Jan 2014American Express
American Express Company

American Express Data Breach

182After Incident
MEDIUM-32
AME306072725
The California Office of the Attorney General reported on January 7, 2014, that American Express Travel Related Services Company, Inc and/or its Affiliates experienced a data breach involving the recovery of American Express Card information. The breach included card account numbers and names but did not compromise Social Security numbers, and no specific number of individuals affected was provided.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
card account numbersnames
DATA BREACH
card account numbersnames
DECEMBER 2013
234Before Incident
Breach
07 Dec 2013American Express
American Express Company

American Express Data Breach

202After Incident
MEDIUM-32
AME514072725
On March 10, 2016, the California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc. The breach occurred on December 7, 2013, and compromised account information of some cardholders, including card numbers and names.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
card numbersnames
DATA BREACH
card numbersnames
SEPTEMBER 2013
237Before Incident
Breach
23 Sep 2013American Express
American Express Company

American Express Data Breach

206After Incident
MEDIUM-31
AME617072725
On September 23, 2013, the California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc. (referred to as AXP). The incident involved the recovery of American Express Card account information, including card numbers and expiration dates; however, Social Security numbers were not affected. The breach date is not available.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
card numbersexpiration dates
DATA BREACH
card numbersexpiration datesSensitivity Of Data: High
JULY 2013
238Before Incident
Breach
03 Jul 2013American Express
American Express Company

American Express Travel Related Services Company Data Breach

206After Incident
MEDIUM-32
AME955072725
The California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc on July 3, 2013. The breach involved the recovery of American Express Card information, including account numbers, names, and Social Security numbers, although the breach date was not specified.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
account numbersnamesSocial Security numbers
DATA BREACH
account numbersnamesSocial Security numbersSensitivity Of Data: High
JUNE 2013
263Before Incident
Breach
13 Jun 2013American Express
American Express Travel Related Services Company, Inc

American Express Travel Related Services Company Data Breach

231After Incident
MEDIUM-32
AME201072925
The California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc. on October 1, 2014. The breach occurred on June 13, 2013, and involved unauthorized access to a merchant's website files, compromising American Express card account numbers, names, and other card information, but not Social Security numbers. The number of affected individuals is unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express card account numbersnamesother card information
DATA BREACH
American Express card account numbersnamesother card information
MAY 2013
289Before Incident
Breach
28 May 2013American Express
American Express Company

American Express Data Breach

258After Incident
MEDIUM-31
AME506072725
The California Office of the Attorney General reported on December 12, 2013, that American Express Travel Related Services Company, Inc. experienced a data breach on May 28, 2013, involving unauthorized access to a merchant's website files. The breach potentially exposed American Express Card account numbers and names, but Social Security numbers were not impacted.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card account numbersNames
DATA BREACH
American Express Card account numbersNames
APRIL 2013
305Before Incident
Breach
09 Apr 2013American Express
American Express Company

American Express Data Breach

273After Incident
MEDIUM-32
AME203072725
The California Office of the Attorney General reported that American Express Travel Related Services Company, Inc. experienced a data breach on April 9, 2013, which was reported on May 2, 2013. The breach involved the recovery of American Express Card information, including account numbers and names, but Social Security numbers were not impacted.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card informationaccount numbersnames
DATA BREACH
American Express Card informationaccount numbersnames
MARCH 2013
324Before Incident
Breach
01 Mar 2013American Express
American Express Company

American Express Data Breach

292After Incident
MEDIUM-32
AME519072525
The California Office of the Attorney General reported on March 1, 2013, that American Express experienced a data breach involving its Cardmembers' information being recovered during a law enforcement investigation. The breach reportedly included American Express Card account numbers and names, but did not compromise Social Security numbers.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card account numbersnames
DATA BREACH
American Express Card account numbersnames
FEBRUARY 2013
347Before Incident
Breach
01 Feb 2013American Express
American Express Travel Related Services Company, Inc.

American Express Travel Related Services Data Breach

316After Incident
MEDIUM-31
AME342072825
The California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc. on July 19, 2013. The breach occurred on February 1, 2013, and involved unauthorized access to data files that included Card account numbers and holder names, but Social Security numbers were not impacted.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Card account numbersHolder names
DATA BREACH
Card account numbersHolder names
JANUARY 2013
375Before Incident
Breach
15 Jan 2013American Express
American Express Company

American Express Travel Related Services Company Data Breach

343After Incident
CRITICAL-32
AME315072525
The California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc. on August 23, 2013. The breach occurred on January 15, 2013, and involved unauthorized access to a payment processing service, potentially exposing account information of some Cardmembers including names, card numbers, expiration dates, and security codes, although Social Security numbers were not impacted.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namescard numbersexpiration datessecurity codes
DATA BREACH
namescard numbersexpiration datessecurity codesSensitivity Of Data: High
DECEMBER 2012
399Before Incident
Breach
19 Dec 2012American Express
American Express Company

American Express Travel Related Services Data Breach

367After Incident
HIGH-32
AME527072925
The California Office of the Attorney General reported that American Express Travel Related Services Company, Inc. experienced a data breach on December 19, 2012, involving unauthorized access to a merchant's website. Approximately UNKN individuals were potentially affected, with the compromised data including American Express Card account numbers and names, but not Social Security numbers.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card account numbersNames
DATA BREACH
American Express Card account numbersNamesNumber Of Records Exposed: UNKN
DECEMBER 2012
427Before Incident
Breach
30 Nov 2012American Express
American Express Travel Related Services Company, Inc.

American Express Data Breach

395After Incident
HIGH-32
AME601072625
The California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc and/or its Affiliates (AXP) on November 30, 2012. The recovered data reportedly included American Express Card account numbers, names, expiration dates, and Social Security numbers, but the exact number of individuals affected and the specific method of the breach are unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card account numbersnamesexpiration datesSocial Security numbers
DATA BREACH
American Express Card account numbersnamesexpiration datesSocial Security numbersSensitivity Of Data: High
OCTOBER 2012
446Before Incident
Breach
10 Oct 2012American Express
American Express Travel Related Services Company, Inc.

American Express Data Breach

414After Incident
MEDIUM-32
AME505072725
The California Office of the Attorney General reported on October 10, 2012, that American Express Travel Related Services Company, Inc. experienced a data breach involving American Express Card information. The affected data included Card account numbers, names, and expiration dates, but Social Security numbers were not compromised; the specific number of individuals affected is unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Card account numbersNamesExpiration dates
DATA BREACH
Card account numbersNamesExpiration dates
AUGUST 2012
466Before Incident
Breach
24 Aug 2012American Express
American Express Company

American Express Data Breach via Merchant Website (2012)

434After Incident
HIGH-32
AME956091725
On August 24, 2012, American Express Travel Related Services Company, Inc. experienced a data breach due to unauthorized access to a merchant's website. The incident, reported by the California Office of the Attorney General on February 19, 2013, resulted in the compromise of American Express Card account numbers, cardholder names, and other payment-related details. However, Social Security numbers were not affected, and the exact number of impacted individuals remains undisclosed. The breach stemmed from a vulnerability in the merchant’s system, allowing attackers to exploit weaknesses and gain access to sensitive cardholder data. While the exposed information could potentially facilitate fraudulent transactions or identity theft, the absence of Social Security numbers or broader personal identifiers limited the severity of the long-term consequences. American Express likely initiated containment measures, including notifying affected customers and collaborating with law enforcement to mitigate risks. The incident underscores the persistent threats posed by cybercriminals targeting payment systems, emphasizing the need for robust security protocols across third-party vendors.
INCIDENT DETAILS -
TYPE
data breach
IMPACT
card account numberscardholder namesother card information (excluding SSNs)merchant's websiteIdentity Theft Risk: potential (card information exposed)Payment Information Risk: high (card account numbers compromised)
DATA BREACH
payment card datapersonal identifiers (names)Number Of Records Exposed: unknownSensitivity Of Data: high (payment card details)Data Exfiltration: yesPersonally Identifiable Information: partial (names only, no SSNs)
JULY 2012
489Before Incident
Breach
12 Jul 2012American Express
American Express Company

American Express Data Breach

457After Incident
MEDIUM-32
AME425072625
The California Office of the Attorney General reported on July 12, 2012, that American Express Travel Related Services Company, Inc. experienced a data breach resulting in the recovery of American Express Card information, including account numbers, names, and expiration dates. Social Security numbers were not impacted, and there was no indication of unauthorized activity.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
account numbersnamesexpiration dates
DATA BREACH
account numbersnamesexpiration dates
JUNE 2012
513Before Incident
Breach
03 Jun 2012American Express
American Express Company

American Express Data Breach

481After Incident
MEDIUM-32
AME159072725
The California Office of the Attorney General reported that American Express Travel Related Services Company, Inc. experienced a data breach on June 3, 2012. The breach involved unauthorized access to a merchant's website files which potentially exposed American Express Card account numbers, names, and other card information, affecting an unspecified number of individuals.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card account numbersnamesother card information
DATA BREACH
American Express Card account numbersnamesother card information
MAY 2012
542Before Incident
Breach
21 May 2012American Express
American Express Travel Related Services Company, Inc.

American Express Data Breach

510After Incident
MEDIUM-32
AME223080425
The California Office of the Attorney General reported that American Express Travel Related Services Company, Inc. experienced a data breach on May 21, 2012. The breach potentially exposed American Express Card account numbers, names, and expiration dates, affecting an unknown number of individuals. However, Social Security numbers were not compromised.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card account numbersnamesexpiration dates
DATA BREACH
American Express Card account numbersnamesexpiration datesNumber Of Records Exposed: Unknown
APRIL 2012
566Before Incident
Breach
02 Apr 2012American Express
American Express Company

American Express Travel Related Services Company Data Breach

534After Incident
MEDIUM-32
AME957072625
The California Office of the Attorney General reported a data breach involving the American Express Travel Related Services Company, Inc. on September 13, 2012. The breach occurred on April 2, 2012, involving unauthorized access to a merchant's data files, exposing American Express Card account numbers, names, and expiration dates, but not Social Security numbers. The number of individuals affected is unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card account numbersnamesexpiration dates
DATA BREACH
American Express Card account numbersnamesexpiration dates
MARCH 2012
593Before Incident
Breach
02 Mar 2012American Express
American Express Company

American Express Travel Related Services Data Breach

561After Incident
MEDIUM-32
AME218072825
The California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc and/or its Affiliates on August 14, 2012. The breach occurred on March 2, 2012, due to unauthorized access to merchant data files potentially exposing American Express Card account numbers, names, and expiration dates, but not Social Security numbers.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card account numbersnamesexpiration dates
DATA BREACH
American Express Card account numbersnamesexpiration dates
FEBRUARY 2012
621Before Incident
Breach
02 Feb 2012American Express
American Express Company

American Express Travel Related Services Company Data Breach

589After Incident
HIGH-32
AME336072625
The California Office of the Attorney General reported a data breach at American Express Travel Related Services Company, Inc. on February 2, 2012. The breach involved unauthorized access to data files, exposing Card account numbers, names, and expiration dates. Social Security numbers were not impacted. The number of individuals affected is unknown. This incident highlights the vulnerability of financial information and the importance of robust cybersecurity measures to protect sensitive data.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Card account numbersNamesExpiration dates
DATA BREACH
Card account numbersNamesExpiration datesNumber Of Records Exposed: UNKN
JANUARY 2012
651Before Incident
Breach
17 Jan 2012American Express
American Express Company

American Express Data Breach

619After Incident
MEDIUM-32
AME706080425
The California Office of the Attorney General reported a data breach affecting American Express Travel Related Services Company, Inc. and/or its Affiliates on August 27, 2013. The breach occurred on January 17, 2012, involving unauthorized access to a merchant's website, potentially exposing American Express Card account numbers and other card information. The number of affected individuals is unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card account numbersOther card information
DATA BREACH
American Express Card account numbersOther card information
DECEMBER 2011
682Before Incident
Breach
30 Dec 2011American Express
American Express Company

American Express Data Breach (2011-2013)

649After Incident
HIGH-33
AME954091725
The California Office of the Attorney General disclosed a data breach affecting American Express Travel Related Services Company Inc. in February 2013, originating from an incident on December 30, 2011. The breach exposed Cardmember account numbers, names, and expiration dates, though Social Security numbers remained uncompromised. The exact number of impacted individuals was not disclosed, leaving the scale of exposure uncertain.The exposed data—primarily financial in nature—poses risks such as fraudulent transactions, identity theft (limited to payment card details), and potential reputational harm to both customers and the company. While no direct financial losses or systemic disruptions were reported, the breach underscores vulnerabilities in payment card security protocols, raising concerns over customer trust erosion and regulatory scrutiny. The absence of Social Security numbers mitigates severe identity theft risks, but the exposure of payment card details still aligns with financial-reputation threats typical of targeted cyber incidents in the financial sector.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Cardmember account numbersnamesexpiration datesIdentity Theft Risk: Low (no Social Security numbers compromised)Payment Information Risk: High (account numbers and expiration dates exposed)
DATA BREACH
Cardmember account numbersnamesexpiration datesNumber Of Records Exposed: UnknownSensitivity Of Data: High (payment card details)names
NOVEMBER 2011
709Before Incident
Breach
06 Nov 2011American Express
American Express Travel Related Services Company, Inc.

American Express Data Breach

677After Incident
MEDIUM-32
AME401072725
The California Office of the Attorney General reported a data breach at American Express Travel Related Services Company, Inc. on November 6, 2012. The breach, which occurred on November 6, 2011, affected potentially compromised American Express Card account information. Card account numbers and card expiration dates were impacted, but Social Security numbers were not compromised. The specific number of affected individuals remains unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
card account numberscard expiration dates
DATA BREACH
card account numberscard expiration dates
JULY 2011
732Before Incident
Breach
11 Jul 2011American Express
American Express Company

American Express Data Breach

699After Incident
HIGH-33
AME209080425
The California Office of the Attorney General reported on December 19, 2014, that American Express Travel Related Services Company, Inc. experienced a data breach on July 11, 2011. The incident involved unauthorized access to a merchant's website which potentially exposed American Express Card account numbers and names, although Social Security numbers were not impacted.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card account numbersNames
DATA BREACH
American Express Card account numbersNames
MARCH 2011
756Before Incident
Breach
13 Mar 2011American Express
American Express Company

American Express Data Breach

724After Incident
MEDIUM-32
AME245072925
The California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc and/or its Affiliates on March 13, 2011, which was reported on August 7, 2014. The breach involved unauthorized access to a merchant's website, potentially exposing American Express Card account numbers, names, and other card information, but not Social Security numbers. The number of individuals affected is not specified.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card account numbersnamesother card information
DATA BREACH
American Express Card account numbersnamesother card information
FEBRUARY 2011
787Before Incident
Breach
15 Feb 2011American Express
American Express Company

American Express Data Breach

755After Incident
MEDIUM-32
AME446072625
The California Office of the Attorney General reported on July 21, 2015, that American Express Travel Related Services Company, Inc. experienced a data breach on February 15, 2011, involving unauthorized access to a merchant's website, potentially exposing American Express Card account numbers, names, and other Card information. The breach did not impact Social Security numbers or show any unauthorized activity on the affected accounts.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card account numbersnamesother Card information
DATA BREACH
American Express Card account numbersnamesother Card information
NOVEMBER 2010
816Before Incident
Breach
01 Nov 2010American Express
American Express Travel Related Services Company, Inc.

American Express Travel Related Services Company Data Breach

784After Incident
MEDIUM-32
AME413080525
The California Office of the Attorney General reported a data breach involving American Express Travel Related Services Company, Inc. on December 12, 2012. The breach occurred on November 1, 2010, and resulted in unauthorized access to a merchant's website, potentially compromising American Express Card account numbers, names, and expiration dates, but not Social Security numbers. The number of affected individuals is unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card account numbersnamesexpiration dates
DATA BREACH
American Express Card account numbersnamesexpiration dates
MAY 2008
834Before Incident
Breach
01 May 2008American Express
American Express Company

American Express Data Breach (2008)

802After Incident
HIGH-32
AME1005091725
In May 2008, American Express Travel Related Services Company, Inc. experienced a data breach due to unauthorized access to a merchant’s data files. The incident, reported by the California Office of the Attorney General on November 12, 2015, exposed American Express Card account numbers and related transaction details. While the breach did not compromise Social Security numbers, the exact number of affected individuals remains undisclosed. The unauthorized access suggests a failure in securing third-party merchant systems, potentially allowing attackers to harvest payment card information. Such breaches often lead to financial fraud risks for cardholders, including unauthorized transactions or identity theft attempts. The delayed disclosure (over seven years later) further highlights gaps in incident response and regulatory compliance. Although no direct evidence of misuse was reported, the exposure of card data alone poses significant reputational and operational risks for American Express, eroding customer trust and potentially incurring regulatory penalties.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
American Express Card account numbersrelated informationPayment Information Risk: American Express Card account numbers
DATA BREACH
American Express Card account numbersrelated informationNumber Of Records Exposed: UnknownSensitivity Of Data: Moderate (payment card data, no SSNs)Personally Identifiable Information: No (Social Security numbers not impacted)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for American Express ?
?
What was American Express's A.I Rankiteo Cyber Score in May 2026 ?
?
What was American Express's A.I Rankiteo Cyber Score in April 2026 ?
?
What was American Express's A.I Rankiteo Cyber Score in March 2026 ?
?
What was American Express's A.I Rankiteo Cyber Score in February 2026 ?
?
What was American Express's A.I Rankiteo Cyber Score in January 2026 ?
?
What was American Express's A.I Rankiteo Cyber Score in December 2025 ?
?
What was American Express's A.I Rankiteo Cyber Score in November 2025 ?
?
What was American Express's A.I Rankiteo Cyber Score in October 2025 ?
?
What was American Express's A.I Rankiteo Cyber Score in September 2025 ?
?
What was American Express's A.I Rankiteo Cyber Score in August 2025 ?
?
What was American Express's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on American Express's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with American Express ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view American Express's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?