Earlier quoted context omitted.
The user only gave TikTok permission to use the videos according to the ToS. And considering the majority of TikTok users are children, I think it's hard to justify morally, even if you could make a legal case.
A "data breach" refers to unauthorized access to nonpublic or protected data. Scraping content that is publicly viewable without logging in - or even with logging in, since an account is effectively disposable - is not a "data breach" (as far as any typical usage of the term goes). In hiQ Labs v. LinkedIn, the 9th Circuit (US) ruled that scraping publicly accessible data does not violate the CFAA's "without authoriza…
"use automated scripts to collect information from or otherwise interact with the Services" — this covers the entire scraping operation.
"make unauthorised copies, modify, adapt, translate, reverse engineer, disassemble, decompile or create any derivative works of the Services... or determine or attempt to determine any source code" — e.g. reverse-engineering the X-Argus/X-Gorgon/X-Ladon signing scheme.
"interfere with or attempt to interfere with the proper working of the Services... or bypass any measures we may use to prevent or restrict access to the Services" — TLS-fingerprint spoofing, the empty-200 soft block, and the proxy IP rotation to get around rate limiting.
"use or attempt to use another's account, service or system without authorisation from TikTok, or create a false identity on the Services" — this covers the forged device registrations (fake Android handset + carrier profiles)
"use the Services, without our express written consent, for any commercial or unauthorized purpose" — the website is monetizing the dataset and selling the code itself.