Earlier quoted context omitted.
Users don't normally construct urls by hand. Wouldn't the equivalent more be like: You filled out some form to request a document from the irs. You give the form to the person they give you the document. You notice they dont check ids, so you change the name on the form, and get someone else's document. This definitely seems to fit the definition of fraud: 380 (1) Every one who, by deceit, falsehood or other fraudule…
But... they didn't change their name on the form. They literally just said "I'm still me, but I want this other file now, please." All company data was, in OPs scenario, made public to any and all authenticated users. There is no way to rationally spin this as a malicious act, in my view.
Downloading a number of them and comparing information, however, is not necessarily malicious but rather sketchy.