Hacker News new | ask | show | jobs
by erikabele 5606 days ago
This reminds me of some flaw with Skype's billing system which allowed me to download invoices for virtually every paying business customer just by replacing some chars in a URL. The invoices included a lot of personal details together with various bank account & phone numbers.

Took me 8 months to get someone at Skype to acknowledge the issue; to my knowledge it was never escalated. Wouldn't be surprised if it's still there...