I wouldn't consider it 'legal'
This has been going on for a long time, and as most cell/utility company web sites have integrated everything into an online environment for billing purposes etc it has become easier to do and quicker. It has been going on for a long time but more and more sites are popping up offering call details.
The unfortunate thing is that no cell or utility company is immune to social engineering attempts, so it can't really be stopped. Granted these sites offering these services can be shut down but that doesn't mean you are safe or this can't happen to you or hasn't, people still have the knowledge to do it.
I know a lot of companies telco related that could definately beef up authentication especially via phone and train employees better. Unfortunately, there is always one stupid rep out there that will not follow proper procedures.
