Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Ban on PFAS products expands in 2026 as US state law takes effect

DESI completes the largest space map in history

Fashion retailer Express left customers’ personal data and order details exposed on the internet

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Fashion retailer Express left customers’ personal data and order details exposed on the internet
Startups

Fashion retailer Express left customers’ personal data and order details exposed on the internet

By April 16, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Fashion giant Express has patched its website to fix a security flaw that allowed anyone to view other people’s order details and personal information, TechCrunch has learned exclusively. At least a dozen Express customer orders were publicly visible in Web search engine results.

The security flaw exposed the order confirmation page of Express’s online store, revealing details about purchases and who made them.

The leaked information included customer names, phone numbers, and email addresses. Postal code, billing address, and shipping address. Order details, including the products purchased by the customer. Part of your payment card information, including card type and last four digits.

Express is a leading clothing retailer with hundreds of stores throughout the United States, Mexico, and Latin America. The formerly publicly traded company is now run by WHP Global, which also owns several fashion and retail giants.

Security and privacy advocate Rey Bango discovered the flaw by chance after investigating fraudulent purchases on a family member’s account, but couldn’t find a way to report the flaw to Express. Bango asked TechCrunch to alert the company to fix the bug.

“When I tried to use Google to find out if the order number was a legitimately formatted Express order number, I saw a link to another order and other people’s order information,” Bango told TechCrunch.

TechCrunch has verified that the address on the order confirmation web page can be tweaked to view other customers’ orders and personal information. Express uses nearly sequential order numbers, so you could easily cycle through thousands of orders by using automated web tools to change the order number in a web address.

When we contacted Express, the apparel giant fixed the flaw on Wednesday but did not say whether it planned to notify customers of the security lapse.

Reached for comment, Joe Berrian, Express’ head of marketing, told TechCrunch: “We take the security and privacy of our customer information seriously and encourage anyone who identifies potential security concerns to contact us directly.”

“We are aware of this matter, have investigated it and continue to review it, but have no further comment at this time,” Berean said.

Berian did not say how customers can contact the company or elaborate on whether the company plans to update its website to receive reports of security flaws, such as through a vulnerability disclosure program. He did not say whether the company has logs or other technical means to see if someone has accessed other customers’ personal information.

The executive did not respond to subsequent questions, including whether Express plans to disclose the incident to state attorneys general as required by U.S. data breach notification laws.

The Express security breach is the latest incident in recent months where misconfigurations and inadvertent security breaches have left customer information exposed on the internet.

In December, a security researcher discovered that Home Depot had exposed its internal systems for a year, but had trouble alerting the company to the incident. That same month, veterinary and pet wellness giant Petco shut down its website after TechCrunch discovered that its Vetco clinic site had leaked customers’ personal information and pet medical documents.


Source link

#Aceleradoras #CapitalRiesgo #EcosistemaStartup #Emprendimiento #InnovaciónEmpresarial #Startups
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleThis simulation startup wants to be the Cursor of physics AI
Next Article DESI completes the largest space map in history

Related Posts

This simulation startup wants to be the Cursor of physics AI

April 16, 2026

Ford EV and technology chief leaves automaker

April 15, 2026

Wait, could they actually break up Live Nation?

April 15, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Ban on PFAS products expands in 2026 as US state law takes effect

DESI completes the largest space map in history

Fashion retailer Express left customers’ personal data and order details exposed on the internet

This simulation startup wants to be the Cursor of physics AI

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.