I've always wondered, aren't these types of bug investigations illegal? Aren't the investigators concerned about criminal prosecution? Not being snarky; I'm asking sincerely.
However, some companies (including Facebook) have a bug bounty program that provides a prescribed safe harbor that you can operate within to discover vulnerabilities within their products or infrastructure in exchange for some kind of recognition or award.
The terms of Facebooks bounty are here: https://www.facebook.com/whitehat
Based on a cursory glance and the fact that this individual was awarded in their program, it appears they operated by the book.
Prosecuting activity that happens outside of these parameters has definitely happened in the past and will continue. It's not always a cut and dried decision. It can be difficult/expensive to effectively prosecute and you may find a lot of social backlash depending on the nature and impact of the activity.