BT's website allows anyone to add paid-for extras to your phone package, using nothing more than your phone number and postcode.The flaw, discovered by a reader of The Register, allows landline tariffs to be upgraded with various call packages and features such as caller display, without having to once enter a login or password.
Instead, all the user has to enter is the landline number and postcode, which is freely available from sources such as BT's own Phone Book site. It raises the possibility that costly extras could be added to customers' accounts without their knowledge.
Read more:
http://www.pcpro.co.uk/news/security/378364/bt-website-lets-anyone-upgrade-your-phone-package