There was also that time when it was trivial to login to
every single Hotmail account by only knowing the username.
And it was left like this for at least 12 hours after it was first reported in media...
http://edition.cnn.com/TECH/computing/9908/30/hotmail.03/
https://slashdot.org/story/99/08/30/1324206/hotmail-cracked-...