Someone I know did something similar, was arrested in their college dorm, and at the sentencing hearing in federal court was fined and sentenced to 5 years probation, and now has a criminal record. This kid is very very lucky. Obviously they violated the CFAA which carries severe criminal penalties. They engaged in actual hacking without any permission or defined scope. And they exploited the system without any respo…
For anyone who like to hack legally and ethically, check out https://www.hackerone.com/ . If you're very good at hacking devices, software, networks, etc, companies will pay bounties for the vulnerabilities you find thru HackerOne. Looks like they paid out millions in bounty in 2020: https://www.zdnet.com/article/hackerones-2020-top-10-public-bug-bounty-programs/
Companies can mark items as duplicates without fixing the underlying bug for an indefinite period of time. So the 3 vulnerabilities I found all got marked as duplicates without any compensation or even acknowledgement of my time writing up the issues. Felt like a complete waste of time.
If you're great, you can probably find novel stuff better than I was able to, but if you're that great you likely already have plenty of employment opportunities.