Kind of like how someone "hacked" into John Podesta's (during the 2016 elections), but the reality was that he wrote his password on a Post-It note and stuck it on his monitor, or something to that effect.
that doesn't change the hacking charge (which is an informal term for various Computer Fraud and Abuse act statutes). The key criteria is unauthorized access to a computer system, it doesn't matter if you obtained a password trivially or not.
You don't need to wear a black hoodie and be an elite haxor to qualify for cyber crime charges.
Media reported it as a spear phishing attack from a Russian hacker group: https://www.vice.com/en/article/how-hackers-broke-into-john-...
In the past governments have gone after people for doing things like view source and stumbling across PII (https://www.vice.com/en/article/this-is-the-hacking-investig...), or this teen who was arrested for a serious crime for scraping files from the provincial FOIA site by enumerating the ids of files that had been released by the province and placed on the open web with sequential ids (https://www.cbc.ca/news/canada/nova-scotia/freedom-of-inform...). In both cases, the government claimed the information was non-public, even though all it took to get it was an un-authenticated request on the open web. These cases are like leaving your tax documents on the curb and then being surprised when your neighbour knows your income.
I'll be very curious to read the post mortem and find out if this rises to the level of actual hacking, or if this is just someone in government finding a scapegoat because they left a bunch of shit that was supposed to be "non-public" on the open web and expected no one to find it.
If you're even a bit hacky yourself, you might not see the internet the same way yourself either. Consider little tricks like looking at urls and trying others that fit the pattern; or hitting view source in order to download a pesky image... etc etc.
https://www.cbc.ca/news/canada/nova-scotia/teen-accused-foi-...
https://www.theregister.com/security/2018/05/07/hacking-char...
https://globalnews.ca/news/7590375/ns-foipop-website-back-on...
I believe it's safe to call it "non public" if the agents needed to "guess the file names" [1] How is it different from, say, guessing a password?
[1] https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...
I would argue that the web server's reply counts as a communication. The argument "but we didn't intend to grant access" goes so far, because what other information do I base myself on to guess that you didn't?
Roughly speaking, that is. Because, despite the fact that this would appear to be a straightforward uncontested and literal communication logged and timestamped by both sides and their respective server and user agents; lawyers somehow fall back to analogies instead.
Assume that an attacker generates a random credit number and attempts to make a purchase online. VISA honours the number and processes the payment. Is the attacker not guilty because VISA's server didn't return a 403 Forbidden (or 401)?
When you download a file from a public S3 bucket, for example, you get a signed URL that expires after a certain date. If someone guesses the signature and downloads the file, are they not guilty because the web server did not return a 200?
If someone guesses your password and reads your mail, is it ok because the IMAP server did not return an error?
I agree that if you deliberately provide false credentials to the server, then the server was misled, and you probably knew you were misleading it, and you probably also know that that 200 OK is not really earned. So Mens Rea cuts against you.
On the other hand, what if you're just coming in blind, asking about URLs in general?
That's actually pretty typical these days where 'your'[1] view of the world at some point in time might be constrained to that HTTP traffic alone.
Accidents notwithstanding, you can't really blame me for believing what I'm told, at least.
"May I GET this, or this, or that?" -> "200 OK" ... it'd be a bit weird to get the cops after me, months later, after I've probably already even forgotten I ever did that wget or curl.
[1] via software/user agent/llm agent/all three
Sending get requests and having a server respond with a document is just how the internet works. If - big if - that is what happened, then someone is going to have to explain why those supposedly private documents were available to anyone who asked using a protocol designed to distribute documents publicly. Enumerating urls isn’t typically regarded as outright illegal.