American Express® Targeted Analysis Program—helping you target data incidents.

 

 

Protect your customers and your brand by quickly targeting and analyzing potential Cardholder data compromises.

TAP Computer Illustration

What is a Cardholder data compromise?

 

Cardholder data compromise occurs when Cardholder data is lost or stolen. American Express Targeted Analysis Program (TAP) is designed to identify potential Card data losses for our Merchants.

 

Cardholder data compromise can:

1. Happen when a criminal steals data from your Cardholder Data Environment.

2. Occur even if you don’t store Card numbers.

3. Be very difficult for you to detect.

 

 

Categories of Cardholder data compromise include, but aren’t limited to:

 

role="none"

Common Point of Purchase (CPP):

American Express Cardmembers report fraudulent transactions on their Card accounts that, potentially, originated from a purchase(s) at your establishment(s).

Card Data Found:

American Express Card and Cardholder data found online are linked to transactions at your establishments.

role="none"

Malware Suspected:

American Express suspects you’re using software infected with or vulnerable to malicious code.

What to do if you hear from us.

 

If we suspect a potential Cardholder data compromise has occurred or is occurring, we’ll attempt to notify you via email, mail or phone. When you hear from us, you’ll need to follow these steps:

Contact Amex
Step 1

Respond

Have the person in your office who handles data security contact us at AXPDataSecurity@aexp.com.


Step 2

Review

Look for security gaps in your Cardholder Data Environment.

 

Tip: Follow Payment Card Industry Data Security Standard (PCI DSS) Guidance and include any supporting systems and third parties in your review. We may provide additional guidance or support as we work with you.

 


Step 3

Report

Send an update about any security gaps you find to AXPDataSecurity@aexp.com.


Step 4

Remediate

Fix the security gaps found during your review.

 

Important: If you confirm a data incident has likely occurred, you have 72 hours from discovery to notify the American Express Enterprise Incident Response Program


Step 5

Validate

Provide us with updated PCI DSS Validation documents as explained in Section 5 of our Data Security Operating Policy

How we help you check for security gaps.

 

Whether evaluating your Cardholder Data Environment for security gaps proactively (recommended) or after receiving a notification from us about a potential Cardholder data compromise, the Targeted Analysis Program includes the following options for your convenience.

Your own technology personnel may review your Cardholder Data Environment for security gaps based on current Payment Card Industry Data Security Standard (PCI DSS) guidance. Here are a few resources to help:

 

  • Website Compromise Checklist – A select list of PCI DSS requirements most often associated with potential compromises involving your website or e-commerce site.
  • Payment Card Industry (PCI) Self-Assessment Questionnaire (SAQ) – A series of yes-or-no questions to help you assess security for Cardholder data. American Express provides Merchants with a SecureTrust PCI Manager account to help you determine which SAQ is right for you based on your Card-acceptance methods.
  • External Vulnerability Scan – A scan conducted by an Approved Scanning Vendor to identify “high-risk” vulnerabilities requiring resolution. We recommend this scan if your Cardholder Data Environment connects to the internet—even if it’s not required by PCI DSS. We also provide our Merchants who are enrolled in the American Express PCI Compliance Program with a SecureTrust PCI Manager account which includes external vulnerability scans for up to five endpoints (including your ecommerce site) at no cost to you.

If you have questions, contact your American Express Client Manager or send us an email.

 

American Express is not responsible for your use of the information provided under the Targeted Analysis Program or any assumptions or conclusions you might draw from its use.  American Express does not guarantee or warranty performance of any third party you elect to use.

Answers to common questions.

Don't Do Business Without It