An American Express employee is being investigated for accessing card holder information and potentially using it to open accounts at other financial institutions.

Starting on September 30th, 2019, American Express began sending out data breach notifications to cardholder members whose information was fraudulently accessed by an employee.

According to this notification, an employee was accessing the information for cardholders and potentially using it to perform identity theft by fraudulently opening accounts at other financial institutions.

"It was brought to our attention that personal information, related to your American Express Card account listed above, may have been wrongfully accessed by one of our employees in an attempt to conduct fraudulent activity, including potentially opening accounts at other financial institutions. In response, we immediately launched an investigation and are fully cooperating with law enforcement agencies to further their investigation."

The information that was accessed for affected members includes the full name, physical and/or billing address, Social Security numbers, birth dates, and the credit card number.

While the notifications are titled "Notice of Data Breach", this is not the same type of data breach that we commonly report on. No systems were hacked or databases stolen.

Instead this was an employee of American Express accessing information when they were not supposed to in order to use it for fraudulent purposes.

In a statement to BleepingComputer, AMEX has stated that the person is no longer employed by them and is currently under criminal investigation.

"We are aware of this issue. Ensuring the security of our customers’ information is our top priority, and we are investigating this matter in close partnership with law enforcement," American Express told BleepingComptuer via email. "We can tell you the person in question is no longer an employee of American Express. Given this is an active criminal investigation, we can’t provide any further comment."

For those who are affected, American Express is offering free credit monitoring through Experian Identity Works. To enroll, the AMEX data breach notification will contain an activation code and order number that needs to be used when registering the service.

It is also strongly advised that victims monitor their credit report and statements for any fraudulent activity and immediately report it to their financial institution.

A full copy of the data breach notification can be read at the Montana Department of Justice.

H/T Hacknotice.com