Fashion retailer Express left customers’ personal data and order details exposed to the internet
Business

Fashion retailer Express left customers’ personal data and order details exposed to the internet

TechCrunch·3h ago·Fear

What Happened

Fashion retailer Express patched a security flaw that exposed customer order details and personal information on the internet. At least a dozen orders were visible in search results. The vulnerability revealed customer names, addresses, phone numbers, email addresses, purchase details, and partial payment card information. Security advocate Rey Bango discovered the flaw while investigating fraud. Express fixed the issue after TechCrunch contacted the company but declined to confirm customer notifications.

Key Entities

ExpressTechCrunchRey BangoWHP GlobalJoe BereanHome DepotPetco

AI Tools