This request is neither threatening nor burdensome. This is a pretty standard run-of-the-mill GDPR request. We get them all the time.
It took less than 60 seconds of my time to provide our support team with the information they needed to respond to the request. In fact, we already have a canned response to these requests - the person on the support team is a new hire and was unaware.
If your org has users/customers in the EU, you need to have a GDPR playbook. Your support team needs to be briefed on these requests and how they should respond.
I have a difficult time believing that any "controller" complaining about this is properly prepared to respond to GDPR access requests.... Which is kind of the whole point of the study, no?