He claims to have downloaded the content listed below. And he is surprised that Facebook responds coldly? Note the string "private keys" in this list... Doesn't the author know how long it will take them to recover from this breech? How much it will cost them?
On the other hand, it does sort of re-enforce the idea that he should be paid handsomely, doesn't it? :)
* Static content for Instagram.com websites. Write access was not tested, but seemed likely.
* Source code for fairly recent versions of the Instagram server backend, covering all API endpoints, some image processing libraries, etc.
* SSL certificates and private keys, including both instagram.com and *.instagram.com
* Secret keys used to sign authentication cookies for Instagram
* OAuth and other Instagram API keys
* Email server credentials
* iOS and Android app signing keys
* iOS Push Notifications keys
* Twitter API keys
* Facebook API keys
* Flickr API keys
* Tumblr API keys
* Foursquare API keys
* Recaptcha key-pair