7 ms·
At least one person has received significant jail time for doing exactly that: https://www.justice.gov/usao-nj/pr/new-york-man-sentenced-41-months-prison-hackin
by gnfargbl 1mo ago
At least one person has received significant jail time for doing exactly that: https://www.justice.gov/usao-nj/pr/new-york-man-sentenced-41-months-prison-hacking-att-s-servers https://www.justice.gov/usao-nj/pr/new-york-man-sentenced-41...
It's not straightforward: the conviction was eventually vacated (without really addressing the substantive point), and it is possible that the US authorities went particularly heavy in this case for other reasons.
But yes, attacking an unauthenticated API has previously met the threshold for conviction.