Is there evidence he misused the data or the server? Did he download all the data and sold to third parties, spammed the hell out of existing users or anything like that? How is verifying the credentials misuse?
I can't break into an AWS data center to access my data, even if I they didn't have any security and I knew exactly where my data is stored. Not because I could be seeing other people's data but because I'd be trespassing.