Assuming that those third-party services are ones that the public can access via their own web interfaces, such that the only thing unauthorized is the manner in which the APIs are consumed, this would seem (unless I am missing more specific precedent) to fall out of CFAA coverage as a result of the Van Buren v. United States decision.