American Express disclosed in March 2024 that unauthorised access to a third-party merchant processor had exposed customer information. Reported fields include names, card account numbers and expiry dates.
The processor was engaged by merchants rather than by cardholders. American Express said its own systems were not involved, and no figure for affected accounts was published.
The Cardholder Never Chose The Processor
A card number reaches a merchant, then the merchant’s processor, then further intermediaries. Each hop is a copy, and the cardholder selected none of them.
This is the most common shape in the file set: the organisation that was breached is not the organisation the affected person deals with. A notification arriving from a card issuer about a company nobody has heard of is the usual end state.
A Card Number Is The One Identifier That Can Be Reissued
Set against the identity documents and national numbers that recur here, a payment card is unusually well handled. It can be cancelled, reissued and its fraudulent use reversed, and the liability sits with the issuer rather than the holder.
That is worth saying because it is rare. Most of what this database records cannot be reissued at all. Graded medium: no affected-account figure and no processor name were published.
Compiled from the company’s notification and public reporting, listed below. The processor has not been named and no affected-account count was released. Corrections: corrections@forensicpost.com.
- American Express credit cards exposed in third-party data breachBleepingComputer