Earlier quoted context omitted.
I'm no lawyer either, but I imagine that the definition of authorisation is key here. If you're a sysadmin on a company email system, then you do technically have access to everyone's data on that system. However, you're generally limited by company policy that you are not permitted to access/modify that data without direct authorisation, say from the employee themselves or from HR. So, therefore, if you go and read…
But that's gross misconduct or some other fireable offense - a civil matter at best. The only item I can see here is fraud (impersonating the people whose accounts have been taken over), of which the mole would be complicit.
That's been exceptionally controversial, as it can turn contract breach into a federal criminal offence in the US.