Desk live·
ForensicPost
Breaches/Third party/File 24-0306

American Express Card Numbers Exposed Through a Merchant Processor

Card account numbers, names and expiry dates were exposed in March 2024 through a third-party merchant processor. Cardholders had no relationship with the processor and no way to know it held their details.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetAmerican Express
ActorUnattributed
D. Kennedy8 min readConfidence: medium1 source reviewed

American Express disclosed in March 2024 that unauthorised access to a third-party merchant processor had exposed customer information. Reported fields include names, card account numbers and expiry dates.

The processor was engaged by merchants rather than by cardholders. American Express said its own systems were not involved, and no figure for affected accounts was published.

The Cardholder Never Chose The Processor

A card number reaches a merchant, then the merchant’s processor, then further intermediaries. Each hop is a copy, and the cardholder selected none of them.

This is the most common shape in the file set: the organisation that was breached is not the organisation the affected person deals with. A notification arriving from a card issuer about a company nobody has heard of is the usual end state.

A Card Number Is The One Identifier That Can Be Reissued

Set against the identity documents and national numbers that recur here, a payment card is unusually well handled. It can be cancelled, reissued and its fraudulent use reversed, and the liability sits with the issuer rather than the holder.

That is worth saying because it is rare. Most of what this database records cannot be reissued at all. Graded medium: no affected-account figure and no processor name were published.

How we reported this

Compiled from the company’s notification and public reporting, listed below. The processor has not been named and no affected-account count was released. Corrections: corrections@forensicpost.com.

Sources
  1. American Express credit cards exposed in third-party data breachBleepingComputer
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary