What did I miss they did that's illegal? It looked like it downloaded a public docker image, searched around inside, and verified that the key it found was still valid (without making any changes), and then immediately notified them about the issue.
The white-hat line stops at "validated the key was valid". It does not extend to "poking around inside to extract business-confidential customer information".