Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Netflix co-founder and chairman Reed Hastings is stepping down from the board

Fashion retailer Express leaked customers’ personal data and order details online

From the Startup Battlefield to the International Space Station: geCKo Materials Made a Sticky Product

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Luma launches AI production studio with faith-focused Wonder Project

    17 April 2026

    Runway’s CEO Says AI Could Help Hollywood Make 50 Movies Instead of One $100 Million Blockbuster

    16 April 2026

    OpenAI updates its Agents SDK to help enterprises build safer, more capable agents

    16 April 2026

    Reid Hoffman weighs in on the ‘tokenmaxxing’ debate.

    15 April 2026

    Anthropic’s co-founder confirms the company briefed the Trump administration on Mythos

    15 April 2026
  • Apps

    Google now lets you explore the web side-by-side with AI

    17 April 2026

    Canva’s AI assistant can now call on various tools to make designs for you

    16 April 2026

    AI learning app Gizmo soars with 13 million users and $22 million in investment

    16 April 2026

    Adobe’s new Firefly AI assistant can use Creative Cloud apps to complete tasks

    15 April 2026

    How the Freecash rewards app made it to the top of the app stores

    15 April 2026
  • Crypto

    British cryptographer Adam Back denies NYT report that he is Bitcoin creator Satoshi Nakamoto

    9 April 2026

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025
  • Fintech

    Airwallex is set to take on Stripe and the rest of the payments industry — in the physical world

    16 April 2026

    Cash app launches ‘pay later’ feature for P2P transfers

    3 April 2026

    Doss raises $55 million for AI inventory management that connects to ERP

    24 March 2026

    Despite stiff competition, Kalshi, Polymarket CEOs back $35m VC fund projections

    23 March 2026

    Amid legal turmoil, Kalshi is temporarily banned in Nevada

    20 March 2026
  • Hardware

    Amazon Unveils Slimmer Fire TV Stick HD, Opens Ember Artline TVs for Pre-Order

    16 April 2026

    Motorola is suing social platforms and creators over posts raising concerns about speech in India

    16 April 2026

    AI data center startup Fluidstack is in talks for a $1 billion round at an $18 billion valuation months after raising $7.5 billion, report says

    15 April 2026

    Amazon is ending support for older Kindle devices

    9 April 2026

    Intel signs Elon Musk’s Terafab chip project

    8 April 2026
  • Media & Entertainment

    Netflix co-founder and chairman Reed Hastings is stepping down from the board

    17 April 2026

    All we like is soulfulness

    16 April 2026

    Wait, could they still break up Live Nation?

    16 April 2026

    HBO Max is coming to India through an exclusive JioHotstar deal

    15 April 2026

    YouTube Live Streams will now withhold ads during peak engagement to protect the atmosphere

    14 April 2026
  • Security

    Fashion retailer Express leaked customers’ personal data and order details online

    17 April 2026

    Two Americans convicted of helping North Korea steal $5 million in fake IT worker scheme

    16 April 2026

    Sweden blames Russian hackers for attempted ‘catastrophic’ cyberattack on thermal plant

    15 April 2026

    Adobe fixes PDF zero-day security flaw that hackers have been exploiting for months

    15 April 2026

    Someone planted backdoors in dozens of WordPress plugins used on thousands of websites

    14 April 2026
  • Startups

    From the Startup Battlefield to the International Space Station: geCKo Materials Made a Sticky Product

    17 April 2026

    This energy startup’s bet on 100-year-old grid technology is paying off

    16 April 2026

    Hightouch reaches $100M ARR powered by AI-powered marketing tools

    16 April 2026

    StrictlyVC San Francisco is less than a month away

    15 April 2026

    Walmart-owned Flipkart, Amazon are squeezing India’s e-commerce startups

    12 April 2026
  • Transportation

    Lucid Motors Appoints New CEO, Gets More Money From Uber, Saudis

    17 April 2026

    Monarch Tractor collapse ends with takeover by Caterpillar

    16 April 2026

    Ford EV and chief technology officer are leaving the auto industry

    16 April 2026

    Chipmakers AMD, Arm and Qualcomm are investing in this buzzing self-driving technology startup

    15 April 2026

    London is closing in on its first robotaxi service as Waymo begins trials

    15 April 2026
  • Venture

    Anthropic rejects VC funding that values ​​it at $800B+, for now

    16 April 2026

    Financial risk management platform Pillar raises $20 million in rounds led by a16z

    15 April 2026

    Vercel CEO Guillermo Rauch signals IPO readiness as AI agents drive revenue

    14 April 2026

    Nvidia-backed SiFive hits $3.65 billion valuation for open AI chips

    11 April 2026

    How to make the Startup Battlefield Top 20 — and what each company gets regardless

    10 April 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Fashion retailer Express leaked customers’ personal data and order details online
Security

Fashion retailer Express leaked customers’ personal data and order details online

techtost.comBy techtost.com17 April 202603 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Fashion Retailer Express Leaked Customers' Personal Data And Order Details
Share
Facebook Twitter LinkedIn Pinterest Email

Fashion giant Express has patched its website to fix a security flaw that allowed anyone to view other people’s order details and personal information, TechCrunch has learned exclusively. At least a dozen Express customer orders were publicly listed in web search engine results.

The security flaw exposed order confirmation pages on Express’ online store, revealing details of purchases and who made them.

The exposed information included customer names, phone numbers and email addresses. mailing, billing and delivery addresses; order details, including items a customer purchased; and some payment card information, including card type and last four digits.

Express is a major clothing retailer with hundreds of stores in the United States, Mexico and Latin America. The once publicly traded company is now run by WHP Global, which also owns several fashion and retail giants.

Security and privacy advocate Rey Bango accidentally discovered the flaw after investigating a fraudulent purchase on a family member’s account, but found no way to report the flaw to Express. Bango asked TechCrunch to notify the company in an effort to fix the bug.

“When I tried to look up if the order number was a legitimately formatted Express order number via Google, I saw a link to another order and someone else’s order information came up!” Bango told TechCrunch.

TechCrunch has verified that one can modify the address of the order confirmation webpage to view the order and personal information of other customers. Express uses order numbers that are largely sequential, which makes it easy to potentially switch thousands of orders by changing the order number in the web address using automated web tools.

When contacted by Express, the apparel giant fixed the flaw on Wednesday, but did not say whether it plans to notify customers of the security flaw.

When reached for comment, Express chief marketing officer Joe Berean told TechCrunch, “We take the security and privacy of customer information seriously and encourage anyone who identifies a potential security concern to contact us directly.”

“We have just been made aware of this issue, have investigated and are continuing to review the matter and have no further comment at this time,” Berean said.

Berean did not say how customers could contact the company, nor did he specify whether the company plans to update its website to receive reports of security flaws, such as a vulnerability disclosure program. He did not say whether the company had the technical means, such as logs, to check whether someone had accessed the personal information of other customers.

The executive did not respond to follow-up questions, including whether Express planned to disclose the incident to state attorneys general, as required by US data breach notification laws.

The Express security breach is the latest incident in recent months where customer information has been exposed online due to misconfigurations or unintended security lapses.

In December, a security researcher found that Home Depot had been exposing its internal systems for a year, but tried to alert the company to the incident. That same month, veterinary and pet wellness giant Petco took down its website after TechCrunch found that the company’s Vetco Clinics website shared personal customer information and their pets’ medical records.

customers cyber security data data breach details Exclusive express Fashion leaked online order personal personal information retailer
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleFrom the Startup Battlefield to the International Space Station: geCKo Materials Made a Sticky Product
Next Article Netflix co-founder and chairman Reed Hastings is stepping down from the board
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Two Americans convicted of helping North Korea steal $5 million in fake IT worker scheme

16 April 2026

This energy startup’s bet on 100-year-old grid technology is paying off

16 April 2026

Hightouch reaches $100M ARR powered by AI-powered marketing tools

16 April 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Netflix co-founder and chairman Reed Hastings is stepping down from the board

17 April 2026

Fashion retailer Express leaked customers’ personal data and order details online

17 April 2026

From the Startup Battlefield to the International Space Station: geCKo Materials Made a Sticky Product

17 April 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Airwallex is set to take on Stripe and the rest of the payments industry — in the physical world

16 April 2026

Cash app launches ‘pay later’ feature for P2P transfers

3 April 2026

Doss raises $55 million for AI inventory management that connects to ERP

24 March 2026
Startups

From the Startup Battlefield to the International Space Station: geCKo Materials Made a Sticky Product

This energy startup’s bet on 100-year-old grid technology is paying off

Hightouch reaches $100M ARR powered by AI-powered marketing tools

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.