American Express Ordered to Fix Security After Employee Spied on Customer
Australian regulators found American Express had weak security that let employees access customer information they shouldn't see. The company must now fix these problems.
Source
DataBreaches.net
Original headline: AU: American Express ordered to fix security gaps after customer was spied on
Plain-English summary by GetCyberRight. Read the full report at the source above.
The Australian Privacy Commissioner ordered American Express to fix security weaknesses in five of its data systems after finding the company failed to protect against insider threats. An employee was able to spy on a customer's information because the company didn't have proper restrictions on which employees could access specific customer data.
This was especially concerning for vulnerable and high profile customers who need extra privacy protection. This affects American Express cardholders, particularly those in Australia where this investigation took place.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
If you have an American Express card, this means employees may have had access to your account information, transaction history, and personal details even when they had no legitimate business reason to view it. The privacy investigation revealed that the company's security systems were not strong enough to prevent curious or malicious employees from snooping on customer accounts.
If you're an American Express cardholder, here's what to do:
- Review your recent account statements carefully for any unauthorized transactions or suspicious activity.
- Check your account settings and ensure all contact information is current so you receive alerts about account changes.
- Consider setting up transaction alerts through the American Express app or website so you're notified of every purchase.
- If you notice anything unusual on your account, contact American Express immediately and ask for a detailed review of who accessed your account information. For broader protection with any financial account, remember that insider threats are real. Employees at banks, credit card companies, and other financial institutions sometimes abuse their access to customer data. Choose companies that take privacy seriously, enable all available security features on your accounts, and monitor your statements regularly. If a company experiences a privacy violation or gets ordered to improve security, that's actually a good sign that regulators are watching and forcing improvements.
Curated from trusted cybersecurity sources by GetCyberRight
Source: DataBreaches.netStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles

Employees Are Building Their Own Apps With AI Tools
Workers are creating their own software using AI without IT oversight. This trend creates new security challenges for businesses and organizations.
2 min read
Companies Struggle With Employees Creating Their Own AI Tools at Work
Workers are building apps and automation tools using AI without company oversight. This is a workplace security challenge, not a home issue.
2 min readNew Security Company Launches to Protect Online Identities for People and AI
A startup called NewCore raised $66 million to build security tools that protect digital identities. Here is what this means for online safety.
2 min readNew Security Company Focuses on Protecting Digital Identities for People and AI
A startup called NewCore launched with funding to build better identity protection. This signals growing investment in keeping your online accounts and digital identity safe.
2 min read