Hackers from the Tunisian Cyber Army discovered a vulnerability in the official American Express website and managed to perform SQL Injection. They claim to have gained access to 2 GB of data.
CyberWarNews examined the details of the vulnerability and found that the hackers' claims are accurate.
It's unclear whether American Express security officials are aware of what happened on their website and whether they plan to do anything about it. However, as CWN points out, this isn't the first time vulnerabilities have been identified on the site's pages.
So far, no data has been leaked by the hackers, but as they wrote on Twitter, the "biggest leak" is coming "soon.".
[tweet_embed id=305346208661114881]
📧
Subscribe to the SecNews Newsletter

