A fitness tracking app stores workouts at /api/users/9921/workouts. Any logged-in user can change the ID and read another user's full activity history — weight, body stats, location of workouts, daily routine. This is exactly what happened with Peloton.
A dating app returns profile data at /api/profiles/7741. Even if user 7741 has blocked the requester, the API doesn't factor that in — it only checks "are you logged in?" Bumble had this exact issue in 2020. Researchers could also retrieve exact GPS coordinates.
A delivery platform exposes tracking at /api/shipments/SH-40021. Changing the shipment ID returns another customer's name, delivery address, and package contents. Automated enumeration of shipment IDs maps thousands of real home addresses in minutes.