upvote
If there is anything that was a crime (and it totally depends on jurisdiction), it was verifying the key. They used it to see what it could access, and by using it they had unauthorised access to a system
reply
The CFAA is broad enough to make that a crime.
reply
They "validated that the key was valid" by iterating internal repositories and listing the contents of said repos and poking around at what they do/are-for, including, apparently, iterating through customer lists/information.

The white-hat line stops at "validated the key was valid". It does not extend to "poking around inside to extract business-confidential customer information".

reply
People have been arrested for far less. I dunno what the least offensive conviction has been though tbf. Anyone know?
reply