logo

Fashion retailer Express left customers’ personal data and order details exposed to the internet

ID: 9fb54786-33b5-5910-9e31-05102d50f13b

STIX ID: report--9fb54786-33b5-5910-9e31-05102d50f13b

Feed Name: TechCrunch Security News

Threat Score
60/100

Date Published: 2026-04-16

Date Updated: 2026-04-23

Author: Zack Whittaker

...
...

TechCrunch reports that Express had a flaw in its online store where sequential order-number URLs allowed anyone to view other customers' order confirmation pages, exposing names, contact details, postal and billing addresses, order contents, and partial payment card information; the issue was discovered by a researcher, TechCrunch alerted Express, and the company patched the vulnerability but has not stated whether affected customers will be notified or whether access logs can determine if data was accessed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.