A guy went to prison for doing this with AT&Ts public subscriber data. The media didn't do him a favor by calling it a hack.
You accidentally stumbling on something unprotected generally clears you from any liability as long as you stop as soon as you notice it.
Code of conduct for white hat hackers is to explore but not abuse, and report as soon as they have enough clarity on the issue. But there is no legal basis for this avoiding any liability except if a company runs an official bounty program.
In that sense, the OP author could face hacking charges if India has similar laws to the rest of the developed world, and the author doesn't even have the "well intentioned" for their defence since they never reached out: the only defence they have is they did not attempt to profit off it.
IANAL, though :)
the old "HELO" hack