Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    How The Dogist Turned His Passion for Photographing Dogs Into a Media Brand

    April 16, 2026

    Google adds Nano Banana-powered image generation to Gemini’s Personal Intelligence

    April 16, 2026

    Best MacBook Accessories (2026): Chargers, Covers, Keyboards, and More

    April 16, 2026
    Facebook Twitter Instagram
    • Tech
    • Gadgets
    • Spotlight
    • Gaming
    Facebook Twitter Instagram
    iGadgets TechiGadgets Tech
    Subscribe
    • Home
    • Gadgets
    • Insights
    • Apps

      Google adds Nano Banana-powered image generation to Gemini’s Personal Intelligence

      April 16, 2026

      You’ve heard of hybrid cars. Now meet a hybrid cement plant.

      April 16, 2026

      Meta raises Quest 3 and Quest 3S prices due to RAM shortage

      April 16, 2026

      Fashion retailer Express left customers’ personal data and order details exposed to the internet

      April 16, 2026

      Sweden blames Russian hackers for attempting ‘destructive’ cyberattack on thermal plant

      April 16, 2026
    • Gear
    • Mobiles
      1. Tech
      2. Gadgets
      3. Insights
      4. View All

      Best MacBook Accessories (2026): Chargers, Covers, Keyboards, and More

      April 16, 2026

      Anthropic Plots Major London Expansion

      April 16, 2026

      Congress Turns Up Pressure on DHS Over Palantir’s Role in Immigration Crackdown

      April 16, 2026

      The 10 Best MagSafe Phone Grips for Your Butter Fingers (2026)

      April 16, 2026

      March Update May Have Weakened The Haptics For Pixel 6 Users

      April 2, 2022

      Project 'Diamond' Is The Galaxy S23, Not A Rollable Smartphone

      April 2, 2022

      The At A Glance Widget Is More Useful After March Update

      April 2, 2022

      Pre-Order The OnePlus 10 Pro For Just $1 In The US

      April 2, 2022

      Motorola Edge+ Review: It Checks A Lot Of Boxes

      April 2, 2022

      This Smartphone Concept Design Is Different… In A Good Way

      April 2, 2022

      Twitter Just Made Searching Your Direct Messages Better

      April 2, 2022

      That Netflix Price Hike Is Starting To Take Place

      April 2, 2022

      Latest Huawei Mobiles P50 and P50 Pro Feature Kirin Chips

      January 15, 2021

      Samsung Galaxy M62 Benchmarked with Galaxy Note10’s Chipset

      January 15, 2021
      9.1

      Review: T-Mobile Winning 5G Race Around the World

      January 15, 2021
      8.9

      Samsung Galaxy S21 Ultra Review: the New King of Android Phones

      January 15, 2021
    • Computing
    iGadgets TechiGadgets Tech
    Home»Apps»Fashion retailer Express left customers’ personal data and order details exposed to the internet
    Apps

    Fashion retailer Express left customers’ personal data and order details exposed to the internet

    adminBy adminApril 16, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    The exterior of an Express clothing store is seen as the company announces it will close some stores on January 22, 2020 in Plantation, Florida.
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Fashion giant Express has patched its website to fix a security flaw that allowed anyone to view other people’s order details and personal information, TechCrunch has exclusively learned. At least a dozen of Express’ customer orders had been publicly listed in web search engine results.

    The security flaw exposed order confirmation pages on Express’ online store, revealing details of purchases and who made them.

    The exposed information contained customer names, phone numbers and email addresses; postal, billing, and delivery addresses; order details, including the items that a customer purchased; and partial payment card information, including the card type and the last four-digits.

    Express is a large clothing retailer with hundreds of stores across the United States, Mexico and Latin America. The once-publicly listed company is now run by WHP Global, which also owns several fashion and retail giants.

    Rey Bango, a security and privacy advocate, accidentally discovered the flaw after investigating a fraudulent purchase on a family member’s account, but found no way to report the flaw to Express. Bango asked TechCrunch to alert the company in an effort to get the bug fixed.

    “When I tried to look up if the order number was a legitimately formatted Express order number using Google, I saw a link to another order and someone else’s order information came up!” Bango told TechCrunch.

    TechCrunch verified that one could tweak the order confirmation webpage address to view the order and personal information of other customers. Express uses order numbers that are largely sequential, which makes it easy to potentially cycle through thousands of orders by changing the order number in the web address using automated web tools.

    After we contacted Express, the apparel giant fixed the flaw on Wednesday, but would not say if it plans to notify customers of the security lapse.

    When reached for comment, Express’ head of marketing Joe Berean told TechCrunch: “We take the security and privacy of customer information seriously and encourage anyone who identifies a potential security concern to contact us directly.”

    “Upon becoming aware of this issue, we investigated and continue to review the matter and have no further comment at this time,” said Berean.

    Berean would not say how customers could contact the company, nor detail if the company has plans to update its website to receive reports of security flaws, such as a vulnerability disclosure program. He did not say if the company had the technical means, such as logs, to check if anyone had accessed the personal information of other customers.

    The executive did not respond to follow-up questions, including if Express planned to disclose the incident to state attorneys general as required by U.S. data breach notification laws.

    Express’ security lapse is the latest incident in recent months where customers’ information was left exposed to the internet due to misconfigurations or inadvertent security lapses.

    In December, a security researcher found that Home Depot had exposed its internal systems for a year, but struggled to alert the company to the incident. In the same month, veterinary and pet wellness giant Petco took down its website after TechCrunch found the company’s Vetco Clinics site was spilling customers’ personal information and their pets’ medical documents.

    Commerce,Security,cybersecurity,data breach,Exclusive,Express,personal informationcybersecurity,data breach,Exclusive,Express,personal information#Fashion #retailer #Express #left #customers #personal #data #order #details #exposed #internet1776344082

    Customers cybersecurity Data data breach details Exclusive Exposed Express Fashion Internet left Order Personal personal information retailer
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    admin
    • Website
    • Tumblr

    Related Posts

    Google adds Nano Banana-powered image generation to Gemini’s Personal Intelligence

    April 16, 2026

    You’ve heard of hybrid cars. Now meet a hybrid cement plant.

    April 16, 2026

    Meta raises Quest 3 and Quest 3S prices due to RAM shortage

    April 16, 2026
    Add A Comment

    Leave A Reply Cancel Reply

    Editors Picks
    8.5

    Apple Planning Big Mac Redesign and Half-Sized Old Mac

    January 5, 2021

    Autonomous Driving Startup Attracts Chinese Investor

    January 5, 2021

    Onboard Cameras Allow Disabled Quadcopters to Fly

    January 5, 2021
    Top Reviews
    9.1

    Review: T-Mobile Winning 5G Race Around the World

    By admin
    8.9

    Xiaomi Mi 10: New Variant with Snapdragon 870 Review

    By admin
    8.9

    Samsung Galaxy S21 Ultra Review: the New King of Android Phones

    By admin
    Advertisement
    Demo
    iGadgets Tech
    Facebook Twitter Instagram Pinterest Vimeo YouTube
    • Home
    • Tech
    • Gadgets
    • Mobiles
    • Our Authors
    © 2026 ThemeSphere. Designed by WPfastworld.

    Type above and press Enter to search. Press Esc to cancel.