Close Menu
TechBrunchTechBrunch
  • Home
  • AI
  • Apps
  • Crypto
  • Security
  • Startups
  • TechCrunch
  • Venture

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Cerebras IPO brings billions to Benchmark, but VC Eric Vishlier barely attended the meeting

May 14, 2026

OpenAI announces hackers stole some data after latest code security issue

May 14, 2026

Khosla Ventures bets $10 million on Ian Crosby, whose last startup Bench went bankrupt

May 14, 2026
Facebook X (Twitter) Instagram
TechBrunchTechBrunch
  • Home
  • AI

    OpenAI seeks to extend human lifespans with the help of longevity startups

    January 17, 2025

    Farewell to the $200 million woolly mammoth and TikTok

    January 17, 2025

    Nord Security founder launches Nexos.ai to help enterprises move AI projects from pilot to production

    January 17, 2025

    Data proves it remains difficult for startups to raise capital, even though VCs invested $75 billion in the fourth quarter

    January 16, 2025

    Apple suspends AI notification summaries for news after generating false alerts

    January 16, 2025
  • Apps

    Google brings Pixel 6 and new devices to Material3 Expressive, along with other features, to the Pixel 6 and new devices

    September 3, 2025

    Google's NoteBookLM now allows you to customize the tone of your AI podcasts

    September 3, 2025

    Roblox expands the use of age estimation techniques and introduces standardized assessments

    September 3, 2025

    Instagram finally launches the iPad app

    September 3, 2025

    Complete the 2025 Confusion Builder Stage Agenda with the Maximum Scaling Voice

    September 3, 2025
  • Crypto

    Six Stages of Disrupt 2026 — Built for Today’s Tougher Startup Market

    May 13, 2026

    24 hours left until your second pass to Disrupt 2026 is 50% off | TechCrunch

    May 8, 2026

    Battlefield 200 application for startups ends on May 27th

    May 7, 2026

    2 days left: Get 50% off your second pass to Disrupt 2026

    May 7, 2026

    3 days left until you get 50% off your second ticket to Disrupt 2026

    May 6, 2026
  • Security

    OpenAI announces hackers stole some data after latest code security issue

    May 14, 2026

    Spyware Investigator Reveals Russian Government Hackers Trying to Take Over Signal Accounts

    May 14, 2026

    Cisco cuts nearly 4,000 jobs as it expands investment in AI, reports 'record quarterly revenue'

    May 14, 2026

    How the world's largest malware bank is stacked up as hard drives

    May 13, 2026

    The world's largest malware bank is stacked on hard drives

    May 13, 2026
  • Startups

    7 days left: Founders and VCs save over $300 on all stage passes

    March 24, 2025

    AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

    March 24, 2025

    20 Hottest Open Source Startups of 2024

    March 22, 2025

    Andrill may build a weapons factory in the UK

    March 21, 2025

    Startup Weekly: Wiz bets paid off at M&A Rich Week

    March 21, 2025
  • TechCrunch

    OpenSea takes a long-term view with a focus on UX despite NFT sales remaining low

    February 8, 2024

    AI will save software companies' growth dreams

    February 8, 2024

    B2B and B2C are not about who buys, but how you sell

    February 5, 2024

    It's time for venture capital to break away from fast fashion

    February 3, 2024

    a16z's Chris Dixon believes it's time to focus on blockchain use cases rather than speculation

    February 2, 2024
  • Venture

    Cerebras IPO brings billions to Benchmark, but VC Eric Vishlier barely attended the meeting

    May 14, 2026

    Khosla Ventures bets $10 million on Ian Crosby, whose last startup Bench went bankrupt

    May 14, 2026

    Battlefield 200 application for startups ends on May 27th

    May 14, 2026

    Kevin Hertz's A* just closed its third fund at $450 million

    May 12, 2026

    Anthropic warns investors against secondary platforms offering access to stocks

    May 12, 2026
TechBrunchTechBrunch

Fashion retailer Express left customers' personal data and order details exposed on the internet

TechBrunchBy TechBrunchApril 16, 20263 Mins Read
Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Telegram Email


Fashion giant Express has patched its website to fix a security flaw that allowed anyone to view other people's order details and personal information, TechCrunch has learned exclusively. At least a dozen Express customer orders were publicly visible in Web search engine results.

The security flaw exposed the order confirmation page of Express's online store, revealing details about purchases and who made them.

The leaked information included customer names, phone numbers, and email addresses. Postal code, billing address, and shipping address. Order details, including the products purchased by the customer. Part of your payment card information, including card type and last four digits.

Express is a leading clothing retailer with hundreds of stores throughout the United States, Mexico, and Latin America. The formerly publicly traded company is now run by WHP Global, which also owns several fashion and retail giants.

Security and privacy advocate Rey Bango discovered the flaw by chance after investigating fraudulent purchases on a family member's account, but couldn't find a way to report the flaw to Express. Bango asked TechCrunch to alert the company to fix the bug.

“When I tried to use Google to find out if the order number was a legitimately formatted Express order number, I saw a link to another order and other people's order information,” Bango told TechCrunch.

TechCrunch has verified that the address on the order confirmation web page can be tweaked to view other customers' orders and personal information. Express uses nearly sequential order numbers, so you could easily cycle through thousands of orders by using automated web tools to change the order number in a web address.

When we contacted Express, the apparel giant fixed the flaw on Wednesday but did not say whether it planned to notify customers of the security lapse.

Reached for comment, Joe Berrian, Express' head of marketing, told TechCrunch: “We take the security and privacy of our customer information seriously and encourage anyone who identifies potential security concerns to contact us directly.”

“We are aware of this matter, have investigated it and continue to review it, but have no further comment at this time,” Berean said.

Berian did not say how customers can contact the company or elaborate on whether the company plans to update its website to receive reports of security flaws, such as through a vulnerability disclosure program. He did not say whether the company has logs or other technical means to see if someone has accessed other customers' personal information.

The executive did not respond to subsequent questions, including whether Express plans to disclose the incident to state attorneys general as required by U.S. data breach notification laws.

The Express security breach is the latest incident in recent months where misconfigurations and inadvertent security breaches have left customer information exposed on the internet.

In December, a security researcher discovered that Home Depot had exposed its internal systems for a year, but had trouble alerting the company to the incident. That same month, veterinary and pet wellness giant Petco shut down its website after TechCrunch discovered that its Vetco clinic site had leaked customers' personal information and pet medical documents.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

OpenAI announces hackers stole some data after latest code security issue

May 14, 2026

Spyware Investigator Reveals Russian Government Hackers Trying to Take Over Signal Accounts

May 14, 2026

Cisco cuts nearly 4,000 jobs as it expands investment in AI, reports 'record quarterly revenue'

May 14, 2026

The world's largest malware bank is stacked on hard drives

May 13, 2026

How the world's largest malware bank is stacked up as hard drives

May 13, 2026

Ransomware hackers claim breach at Apple, Google, Nvidia electronics giant Foxconn

May 13, 2026

Leave A Reply Cancel Reply

Top Reviews
Editors Picks

7 days left: Founders and VCs save over $300 on all stage passes

March 24, 2025

AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

March 24, 2025

20 Hottest Open Source Startups of 2024

March 22, 2025

Andrill may build a weapons factory in the UK

March 21, 2025
About Us
About Us

Welcome to Tech Brunch, your go-to destination for cutting-edge insights, news, and analysis in the fields of Artificial Intelligence (AI), Cryptocurrency, Technology, and Startups. At Tech Brunch, we are passionate about exploring the latest trends, innovations, and developments shaping the future of these dynamic industries.

Our Picks

Cerebras IPO brings billions to Benchmark, but VC Eric Vishlier barely attended the meeting

May 14, 2026

OpenAI announces hackers stole some data after latest code security issue

May 14, 2026

Khosla Ventures bets $10 million on Ian Crosby, whose last startup Bench went bankrupt

May 14, 2026

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

© 2026 TechBrunch. Designed by TechBrunch.
  • Home
  • About Tech Brunch
  • Advertise with Tech Brunch
  • Contact us
  • DMCA Notice
  • Privacy Policy
  • Terms of Use

Type above and press Enter to search. Press Esc to cancel.