Every online order leaves a trail. A name, an email address, a delivery address, an order history and sometimes a stored card token — gathered in seconds at checkout, then scattered across a website database, an email platform, a shipping tool and a spreadsheet somebody exported two years ago and never deleted. Most retailers file that information under admin. Attackers treat it as inventory.
