Breaking past security systems. So like scraping publicly facing data might violate TOS, but you can't call it hacking. Using exploits to get the password hashes would be criminal hacking.
For instance this: https://www.theguardian.com/technology/2013/mar/18/at-and-t-...
All they did was "scrape publicly facing data"
Slippery slope. I'd gander a guess this will continue to be a case-by-case call.