There was no need to take all that data at all. If he was interested in security he could just set up a test account, test the vuln with that account only, and send Apple the results. Job done. I doubt Apple would bother to prosecute for that, they might even thank him. Do they pay bounties for reports on security vulnerabilities? If not they should.
Taking all the data and publishing it, and then bragging about it on youtube (!) just leaves him open to prosecution, and I imagine Apple will go after him now for publishing the data of their developers.
I'm not sure I understand the logic of publishing this, but there seems to be a mentality of braggadocio among wannabe security researchers -
1. Hack high profile website and publicise it
2. ?????
3. Profit!
I'm not sure what step 2 is.