{"id":234848,"date":"2026-04-16T12:39:56","date_gmt":"2026-04-16T12:39:56","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/04\/16\/exclusive-fashion-retailer-express-left-customers-personal-data-and-order-details-exposed-to-the-internet\/"},"modified":"2026-04-16T12:39:56","modified_gmt":"2026-04-16T12:39:56","slug":"exclusive-fashion-retailer-express-left-customers-personal-data-and-order-details-exposed-to-the-internet","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/04\/16\/exclusive-fashion-retailer-express-left-customers-personal-data-and-order-details-exposed-to-the-internet\/","title":{"rendered":"Exclusive: Fashion retailer Express left customers&#8217; personal data and order details exposed to the internet"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Fashion giant Express has patched its website to fix a security flaw that allowed anyone to view other people\u2019s order details and personal information, TechCrunch has exclusively learned. At least a dozen of Express\u2019 customer orders had been publicly listed in web search engine results.<\/p>\n<p class=\"wp-block-paragraph\">The security flaw exposed order confirmation pages on Express\u2019 online store, revealing details of purchases and who made them.<\/p>\n<p class=\"wp-block-paragraph\">The exposed information contained customer names, phone numbers and email addresses; postal, billing, and delivery addresses; order details, including the items that a customer purchased; and partial payment card information, including the card type and the last four-digits.<\/p>\n<p class=\"wp-block-paragraph\">Express is a large clothing retailer with hundreds of stores across the United States, Mexico and Latin America. The once-publicly listed company is now run by WHP Global, which also owns several fashion and retail giants.<\/p>\n<p class=\"wp-block-paragraph\">Rey Bango, a security and privacy advocate, accidentally discovered the flaw after investigating a fraudulent purchase on a family member\u2019s account, but found no way to report the flaw to Express. Bango asked TechCrunch to alert the company in an effort to get the bug fixed.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhen I tried to look up if the order number was a legitimately formatted Express order number using Google, I saw a link to another order and someone else\u2019s order information came up!\u201d Bango told TechCrunch.<\/p>\n<p class=\"wp-block-paragraph\">TechCrunch verified that one could tweak the order confirmation webpage address to view the order and personal information of other customers. Express uses order numbers that are largely sequential, which makes it easy to potentially cycle through thousands of orders by changing the order number in the web address using automated web tools.<\/p>\n<p class=\"wp-block-paragraph\">After we contacted Express, the apparel giant fixed the flaw on Wednesday, but would not say if it plans to notify customers of the security lapse.<\/p>\n<p class=\"wp-block-paragraph\">When reached for comment, Express\u2019 head of marketing Joe Berean told TechCrunch: \u201cWe take the security and privacy of customer information seriously and encourage anyone who identifies a potential security concern to contact us directly.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cUpon becoming aware of this issue, we investigated and continue to review the matter and have no further comment at this time,\u201d said Berean.<\/p>\n<p class=\"wp-block-paragraph\">Berean would not say how customers could contact the company, nor detail if the company has plans to update its website to receive reports of security flaws, such as a vulnerability disclosure program. He did not say if the company had the technical means, such as logs, to check if anyone had accessed the personal information of other customers.<\/p>\n<p class=\"wp-block-paragraph\">The executive did not respond to follow-up questions, including if Express planned to disclose the incident to state attorneys general as required by U.S. data breach notification laws.<\/p>\n<p class=\"wp-block-paragraph\">Express\u2019 security lapse is the latest incident in recent months where customers\u2019 information was left exposed to the internet due to misconfigurations or inadvertent security lapses.<\/p>\n<p class=\"wp-block-paragraph\">In December, a security researcher found that Home Depot had <a href=\"https:\/\/techcrunch.com\/2025\/12\/12\/home-depot-exposed-access-to-internal-systems-for-a-year-says-researcher\/\" target=\"_blank\" rel=\"noopener\">exposed its internal systems for a year<\/a>, but struggled to alert the company to the incident. In the same month, veterinary and pet wellness giant Petco took down its website after TechCrunch found the company\u2019s <a href=\"https:\/\/techcrunch.com\/2025\/12\/10\/petco-takes-down-vetco-website-after-exposing-customers-personal-information\/\" target=\"_blank\" rel=\"noopener\">Vetco Clinics site was spilling customers\u2019 personal information<\/a> and their pets\u2019 medical documents.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/04\/16\/fashion-retailer-express-left-customers-personal-data-and-order-details-exposed-to-the-internet\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fashion giant Express has patched its website to fix a security flaw that allowed anyone to view other people\u2019s order details and personal information, TechCrunch has exclusively learned. At least a dozen of Express\u2019 customer orders had been publicly listed in web search engine results. The security flaw exposed order confirmation pages on Express\u2019 online [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":234849,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-234848","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/234848","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=234848"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/234848\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/234849"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=234848"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=234848"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=234848"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}