Australia sanctions AmEx
2026-06-15 15:20:22.577491+02 by Dan Lyke 0 comments
Australian Privacy Commissioner orders American Express Australia Limited to compensate complainant following interference in privacy. It takes a couple of clicks to get to the actual report, but it's summarized by Dissent Doe :cupofcoffee: @PogoWasRight@infosec.exchange (who also links to a paywalled news report):
American Express ordered to fix security gaps after a customer complained about improper employee access.
It seems that a customer reported a privacy concern and fought AmEx for 4 years to get them to implement stronger access controls or monitoring of employee access to data.
Now, the AU govt has ordered AmEx to rectify security flaws in five of its data systems to guard against insider threats and to restrict employee access to specific customer information to protect vulnerable and high-profile customers.
From reading through the report, this was a stalking/domestic abuse violation, and AmEx didn't even have access logging, and lacked policy for any sort of reaction to stalking.