A security flaw in Telefnica’s Movistar website exposed billing invoices for millions of customers. The flaw allowed someone viewing an account invoice to increment the invoice number and view someone else’s bill. The data exposed includes names, addresses, email addresses, fixed and mobile numbers and call records. The type of vulnerability is known as insecure direct object reference, says Troy Hunt, an Australian security expert and creator of the Have I Been Pwned data breach notification service. Facua.org calls the exposure the “biggest security breach in the history of telecommunications in Spain””]
Source: https://www.databreachtoday.com/telefonica-movistar-site-exposed-customer-billing-details-a-11213

