Did you have permission to do that ? Sounds pretty risky to be probing the network of a flight imo.
I'm not too concerned about the risk associated with fetching a JSON file that their flight status page is already fetching on a loop. That said, I'm curious what risks you have in mind.
Overzealous prosecutors.
The in-flight webpage was continuously fetching a specific end-point from the in-flight web server.
This end-point is basically public data.
All he did was duplicate what the webpage was already doing, and then do some basic analysis on the data the end-point was returning.