Remix.run Logo
gnfargbl 2 hours ago

At least one person has received significant jail time for doing exactly that: https://www.justice.gov/usao-nj/pr/new-york-man-sentenced-41...

It's not straightforward: the conviction was eventually vacated (without really addressing the substantive point), and it is possible that the US authorities went particularly heavy in this case for other reasons.

But yes, attacking an unauthenticated API has previously met the threshold for conviction.