Fashion retailer Express left customers’ personal data and order details exposed to the internet
Fashion retailer Express exposed sensitive customer data including names, addresses, phone numbers, emails, and partial payment card information through a misconfigured web vulnerability that allowed sequential order number manipulation to access other customers' records. This incident exemplifies a critical pattern of preventable data exposures among major retailers and underscores the urgent need for IT organizations to implement robust access controls, secure APIs, and vulnerability disclosure programs to mitigate data breach risks and regulatory compliance obligations. The company's inability to quickly notify customers and lack of a clear security incident response process highlights the business and reputational damage that inadequate security maturity can inflict on large enterprises.
