Fashion retailer Express left customers’ personal data and order details exposed to the internet

Fashion retailer Express exposed sensitive customer data including names, addresses, phone numbers, emails, and partial payment card information through a misconfigured web vulnerability that allowed sequential order number manipulation to access other customers' records. This incident exemplifies a critical pattern of preventable data exposures among major retailers and underscores the urgent need for IT organizations to implement robust access controls, secure APIs, and vulnerability disclosure programs to mitigate data breach risks and regulatory compliance obligations. The company's inability to quickly notify customers and lack of a clear security incident response process highlights the business and reputational damage that inadequate security maturity can inflict on large enterprises.

TechCrunch2 min read
Read full article
Fashion retailer Express left customers’ personal data and order details exposed to the internet
Retail giant Express was publicly spilling customer information to the open web. The bug is now fixed after TechCrunch alerted Express, but the company would not say if it plans to notify customers.