So for example in the UK with the computer misuse act, intent matters. If you intentionally change an id because you expect you will be able to access other data it becomes a crime.
Your example is flawed because in this case the private data was not made available publicly at all – you need to intentionally exploit a software flaw to access it.
Of course, it also matters how you handle it. If you do enough to just discover the flaw, try to adhere to the bug bounty program scope (if any), use your own accounts in testing and responsibly disclose any findings as soon as you have a poc then you'll probably be ok.
In this case the author went way beyond just finding the flaws, and then disclosed it publicly in a completely irresponsible way without even trying to contact the company or any of the clients affected by it (some of which will certainly have a security contact that can liaise with the vendor)