When applying for a credit card, the holder must provide a list of sensitive information for verification and security. Those information aren't meant for the public to see, and this is why there are considered commodities among hackers and scammers.
This time, American Express Company, the multinational financial services corporation once considered among the top brands in the world, has many of its customers experiencing data leak.
In a hacking forum, a hacker is giving away for free the credit card details of 10,000 American Express users in Mexico.
The data exposes full American Express account (credit card) numbers and customers' personally identifiable information (PII) including name, full address, phone numbers, date of birth, gender, etc.. However, the list does not include sensitive information that would allow the theft of funds.
"I do not sell private data such as password, card information, id number. With the data I sell or share, you are only exposed to spam or marketing :)," stated the seller in the same dark web forum thread.
The leak was first made public on January 3 through the Twitter account of cybersecurity analyst Bank Security.
A Threat Actor shared for free over 10,000 American Express México (@amex_express_mx) customer Data and claimed to also have data from @SantanderMx, @Citibanamex and more. pic.twitter.com/3rmoRrWyR3
— Bank Security (@Bank_Security) January 3, 2021
American Express neither denied nor admitted that they had suffered a data breach.
"We are aware of the report and are closely monitoring the situation. We do not have anything further to share at this time."
"However, as a reminder, American Express Card Members are not liable for any fraudulent charges on their accounts. American Express has sophisticated monitoring systems and internal safeguards in place to help detect fraudulent and suspect activity. If we see there is unusual activity which may be fraud, we will take protective actions," stated American Express to BleepingComputer.
Despite not having credit card expiration dates, passwords, or overly sensitive financial data, the leak can still pose some serious security and privacy issues.
While it seems that the actor behind the forum post intends to expose this data mainly for marketing spam purposes only, the data on experienced hands can be used to extract more data and cause even more damage, like for example, through social engineering attacks.




















































































































































































































































































































































































