The legal system is very complicated and sometimes small details make very big differences in cases. I'm not convinced others in the legal system would see this as different
The legal system is very complicated and sometimes small details make very big differences in cases. I'm not convinced others in the legal system would see this as different
As you and I have essentially both just said, it's very unlikely there would be any prosecution due to the facts and the researcher's intentions, but I think it is still a technical violation. Paraphrasing, but the first line of the CFAA is "having knowingly accessed a computer without authorization or exceeding authorized access" (that line is explicitly for access that could jeopardize national security, but it goes on to set similar limits for general unauthorized access of any entity).
In this case it is not necessarily unauthorized access of a customer's account, but unauthorized access to a component of Moonpig's system.
It's arguable that he could be reverse engineering the API to make a compatible client - I think that should be legal, although IANAL.
In this case there's almost no chance law enforcement would charge the researcher unless Moonpig decided to press charges. And even then, they may decide not to charge due to the facts of the case (though of course they legally can).