Very believable. Many, many years ago when auditing a health company website we found a similar "exploit". If any member of the public created a record, there was a page which was (something like) /display.php?record=123. Needless to say if you altered the ID you could read every other medical record. The company took some persuading to even understand that this was a problem, never mind actually fixing it. (Since this was a commercial job, I won't mention the company name)
It happened as described. Before it happened, I didn't think there were people like that in this world.
To his credit, the family member took it as a life lesson and moved on (probably more than I have given my posting here). These days he deals with companies that value his contributions, and it turns out that his ex-employer's loss is other companies' (significant) gain.