4 ms·
I don't know anything about this breach, but I did find this[1]. It doesn't really have much more data, but it does include a link to a ca.gov site hosting a sa
by colonelxc 14y ago
I don't know anything about this breach, but I did find this[1]. It doesn't really have much more data, but it does include a link to a ca.gov site hosting a sample letter (which probably looks nearly identical to yours).
As far as the credit watching goes, it is not uncommon. I know of a college that lost a bunch of student information did the same thing. Basically the school (or company in this case) in question pays one of the credit institutions to give everyone affected a year of credit monitoring service. I don't know if it actually helps the company in terms of liability, but at least it is a positive PR decision.
I'm not sure why they don't suggest cancelling the card. Maybe someone like AmEx is afraid of people leaving them completely instead of just getting a new card? Feel free to call AmEx and get a new card. Can't hurt, right?
And finally, no, security breaches like this usually are not made public. Actually, it is suspected that most breaches are not reported to anyone at all. For companies that do decide to comply with disclosure laws, they send out letters like this, but usually only to the potentially affected customers (not publicly). When you see something like this in the news, it is either the rare case that the company did announce something publicly, or the more common case where someone like you receives a letter, then runs to the nearest high traffic blogger/news source to report the story. As you can see on http://datalossdb.org http://datalossdb.org, there are multiple incidents being reported every day.
Good luck!
[1] http://datalossdb.org/incidents/6752-amex-notified-company-that-cards-used-on-their-e-commerce-site-had-been-compromised http://datalossdb.org/incidents/6752-amex-notified-company-t...