To exploit BOLA you need exactly three things:
1. A valid account. Sign up for free. Anyone can do this.
2. The ability to look at a URL or a network request. Right-click → Inspect → Network tab. Every browser has this built in.
3. The ability to change a number. That's it. Backspace. Type a different number. Hit enter.
Bug bounty hunters. Bored users. Journalists investigating data practices. Competitors. And yes — criminals who realize no skill is required. The low bar is what makes BOLA the #1 API risk. The data is practically in the open.