My concern is more in relation to trying to use an endpoint from non-public source code, it seems negligent to randomly try endpoints like this
It would be different if they were attempting to brute force credentials to access an endpoint, but they aren’t.
Weev went to jail for accessing public api's, https://en.wikipedia.org/wiki/Weev#AT&T_data_breach
> The flaw was part of a publicly-accessible URL, which allowed the group to collect the e-mails without having to break into AT&T's system.
It was argued that he didn't circumvent, but it didn't stop them from putting him in jail initially.