惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
P
Proofpoint News Feed
D
DataBreaches.Net
C
Check Point Blog
L
LangChain Blog
量子位
美团技术团队
Vercel News
Vercel News
人人都是产品经理
人人都是产品经理
N
Netflix TechBlog - Medium
V
Visual Studio Blog
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
MongoDB | Blog
MongoDB | Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Last Week in AI
Last Week in AI
The GitHub Blog
The GitHub Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
U
Unit 42
腾讯CDC
M
MIT News - Artificial intelligence
Microsoft Azure Blog
Microsoft Azure Blog
Blog — PlanetScale
Blog — PlanetScale

TechCrunch

Robots beat human records at Beijing half-marathon Palantir posts mini-manifesto denouncing inclusivity and ‘regressive’ cultures TechCrunch Mobility: Uber enters its assetmaxxing era Cracks are starting to form on fusion energy’s funding boom Blue Origin successfully re-uses a New Glenn rocket for the first time ever Tesla brings its robotaxi service to Dallas and Houston VC Ron Conway says he has a ‘rare form of cancer’ AI chip startup Cerebras files for IPO Anthropic’s relationship with the Trump administration seems to be thawing The App Store is booming again, and AI may be why Once close enough for an acquisition, Stripe and Airwallex are now going after each other “Tokenmaxxing” is making developers less productive than they think Hackers are abusing unpatched Windows security flaws to hack into organizations Zoom teams up with World to verify humans in meetings Gigs turns your concert history into a personal live music archive Chef Robotics escaped the robot cooking graveyard and says it’s thriving — here’s why Uber will now pick up your returns from your doorstep Anthropic launches Claude Design, a new product for creating quick visuals Google’s AI Mode can now help you find products in stock nearby Bluesky confirms DDoS attack is cause of continued app outages Bluesky confirms DDoS attack is cause of continued app outages Netflix plans to add a vertical video feed, use AI for recommendations SaySo is a new short-form video app that aims to restore users’ trust in news Loop raises $95M to build supply chain AI that predicts disruptions Are we tokenmaxxing our way to nowhere? New leaders, new fund: Sequoia has raised $7B to expand its AI bets Netflix co-founder and chair Reed Hastings to leave board Upscale AI in talks to raise at $2B valuation, says report Physical Intelligence, a hot robotics startup, says its new robot brain can figure out tasks it was never taught From the Startup Battlefield stage to the International Space Station: geCKo Materials built a sticky product
Fashion retailer Express left customers’ personal data an...
Zack Whittak · 2026-04-16 · via TechCrunch

Fashion giant Express has patched its website to fix a security flaw that allowed anyone to view other people’s order details and personal information, TechCrunch has exclusively learned. At least a dozen of Express’ customer orders had been publicly listed in web search engine results.

The security flaw exposed order confirmation pages on Express’ online store, revealing details of purchases and who made them.

The exposed information contained customer names, phone numbers, and email addresses; postal, billing, and delivery addresses; order details, including the items that a customer purchased; and partial payment card information, including the card type and the last four-digits.

Express is a large clothing retailer with hundreds of stores across the United States, Mexico, and Latin America. The once-publicly listed company is now run by WHP Global, which also owns several fashion and retail giants.

Rey Bango, a security and privacy advocate, accidentally discovered the flaw after investigating a fraudulent purchase on a family member’s account, but found no way to report the flaw to Express. Bango asked TechCrunch to alert the company in an effort to get the bug fixed.

“When I tried to look up if the order number was a legitimately formatted Express order number using Google, I saw a link to another order and someone else’s order information came up!” Bango told TechCrunch.

TechCrunch verified that one could tweak the order confirmation web page address to view the order and personal information of other customers. Express uses order numbers that are largely sequential, which makes it easy to potentially cycle through thousands of orders by changing the order number in the web address using automated web tools.

After we contacted Express, the apparel giant fixed the flaw on Wednesday, but would not say if it plans to notify customers of the security lapse.

When reached for comment, Express’ head of marketing Joe Berean told TechCrunch: “We take the security and privacy of customer information seriously and encourage anyone who identifies a potential security concern to contact us directly.”

“Upon becoming aware of this issue, we investigated and continue to review the matter and have no further comment at this time,” said Berean.

Berean would not say how customers could contact the company, nor detail if the company has plans to update its website to receive reports of security flaws, such as a vulnerability disclosure program. He did not say if the company had the technical means, such as logs, to check if anyone had accessed the personal information of other customers.

The executive did not respond to follow-up questions, including if Express planned to disclose the incident to state attorneys general as required by U.S. data breach notification laws.

Express’ security lapse is the latest incident in recent months where customers’ information was left exposed to the internet due to misconfigurations or inadvertent security lapses.

In December, a security researcher found that Home Depot had exposed its internal systems for a year, but struggled to alert the company to the incident. In the same month, veterinary and pet wellness giant Petco took down its website after TechCrunch found the company’s Vetco Clinics site was spilling customers’ personal information and their pets’ medical documents.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.

He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.

View Bio