American Express warns cardholders of breach at third-party merchant processor
- Organization
- American Express
- Exploit
- Third-Party Data Breach
- Industry
- Financial Services
American Express began notifying cardholders in early March 2024 that their account details may have been exposed in a breach at a third party rather than at the card issuer itself. The notification, filed with state regulators including Massachusetts, said a service provider engaged by merchants had suffered unauthorized access to its systems.
According to the notice, the exposed information could include current or previously issued American Express card account numbers, cardholder names and card expiration dates. The company did not say how many customers were affected, did not name the merchant processor involved and did not state when the intrusion occurred.
American Express stressed that its own environment was intact, writing that "American Express owned or controlled systems were not compromised by this incident." It also pushed back on early coverage framing the episode as an attack on the issuer, saying the incident happened at a merchant processor. Security Affairs reported that the provider in question handled travel related reservations for merchants, a detail the notification itself did not spell out.
The company said it monitors accounts for fraudulent and suspicious activity, told cardholders they would not be liable for fraudulent charges, and advised them to review statements, enable transaction alerts and keep contact details current. As of the March 2024 reporting date, neither the scale of the exposure nor the identity of the processor had been disclosed.