Supply chain β›“ Supply Chain

American Express Third-Party Breach (March 2024)

πŸ“… 2024-03-01 🏒 A Merchant Processor
Primary Source β†—

Incident Details

American Express credit cards exposed in third-party data breach. American Express is warning customers that credit cards were exposed in a third-party data breach after a merchant processor was hacked. 3/4/24: Article updated with further clarification from American Express that it was a merchant processor who was hacked, not one of their service providers. This incident was not caused by a data breach at American Express, but rather at a merchant processor in which American Express Card member data was processed. Third-party company: A Merchant Processor.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
A Merchant Processor
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2024-03-01 Breach occurred
  2. 2024-03-04 Publicly disclosed