In the US, hacking laws require intent.
Software behaving differently than intended is therefore not a crime under these laws.
Software behaving differently than intended is therefore not a crime under these laws.
If you think they intentionally had their model hack third-party systems, you could do a criminal investigation.
I do not think that this is reasonable to believe given that clearly the VMs were not intended to have internet access and that committing such crimes wasn't in anyone's interest.
In criminal hacking law that explicitly requires intent, or a civil lawsuit about damages?
I honestly don't know, but my guess would be the latter.