American Express Ordered to Fix Security Flaws After Employee Spied on Customer
Australia's privacy watchdog found American Express failed to protect customer data from insider threats. The company must now restrict employee access.
Source
DataBreaches.net
Original headline: AU: American Express ordered to fix security gaps after customer was spied on
Plain-English summary by GetCyberRight. Read the full report at the source above.
Australia's Privacy Commissioner ordered American Express to fix security problems in five of its data systems. The investigation found that American Express failed to protect against insider threats, situations where employees misuse their access to view customer information they should not see. The company must now restrict which employees can access specific customer data, especially for vulnerable and high-profile customers. This affects American Express customers, particularly those in Australia where the investigation took place. An employee was able to spy on at least one customer's account information without proper oversight or restrictions.
If you have an American Express card, your transaction history, personal details, and account activity could have been visible to employees who had no legitimate business reason to view it.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
If you are an American Express cardholder, take these actions now:
- Review your recent account statements carefully for any unusual activity or unauthorized charges.
- Check your credit report for new accounts or inquiries you did not initiate.
- Consider setting up account alerts through American Express to notify you of all transactions and account changes.
- If you notice anything suspicious, contact American Express immediately and request a detailed review of who accessed your account information. You cannot control how employees at financial institutions use their access to your data, but you can monitor your accounts closely to catch problems early. For better long-term protection, regularly review statements from all your financial accounts, not just American Express. Set up automatic alerts for transactions over a certain amount. Check your credit reports at least once per year through the official free credit report services. Insider threats are difficult to prevent as a customer, but quick detection of unauthorized activity limits the damage. If a financial institution contacts you about security improvements, pay attention to what changed and what new protections they offer.
Curated from trusted cybersecurity sources by GetCyberRight
Source: DataBreaches.netStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles

Employees Are Building Their Own Apps With AI Tools
Workers are creating their own software using AI without IT oversight. This trend creates new security challenges for businesses and organizations.
2 min read
Companies Struggle With Employees Creating Their Own AI Tools at Work
Workers are building apps and automation tools using AI without company oversight. This is a workplace security challenge, not a home issue.
2 min readNew Security Company Launches to Protect Online Identities for People and AI
A startup called NewCore raised $66 million to build security tools that protect digital identities. Here is what this means for online safety.
2 min readNew Security Company Focuses on Protecting Digital Identities for People and AI
A startup called NewCore launched with funding to build better identity protection. This signals growing investment in keeping your online accounts and digital identity safe.
2 min read