Express
Disclosed Apr 16, 20265 months agoUnverified
Express order page flaw exposed customer contact and order details
A flaw in Express order confirmation pages let anyone cycle through sequential order numbers to view customers' names, contact and delivery details, purchases and card type with last four digits. Express fixed the bug after TechCrunch reported it.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Apr 16, 2026 |
| Attack | Exposed data |
| Data exposed | Names, Phone numbers, Emails, Addresses, Payment cards, Other |
| Sector | Retail · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| Fashion retailer Express left customers' personal data and order details exposed to the internettechcrunch.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Apr 16 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.