I am in no way a security expert but considering I was able to attack, change passwords and DDOS a company's web access portal with a few year old smartphone, you should be worried!
I informed the company the best they would allow for an outsider to do so but I feel this may not be only centered around a single company so I wrote a public report of my experiment and findings.
Read it here: https://tinyurl.com/ycr6d2kd
This is hilarious.