Earlier quoted context omitted.
I was about to post a similar comment to yours until I clicked through to the linked AMA below and saw some of his GNAA history. Given that history, it's really easy to claim that he was intending to do harm with that list of emails, and it's also pretty easy to think of ways for him to do harm. Idendity fraud might be a bit of a reach, but computer abuse with malevolent intent? Not too hard to get there from his pub…
Those emails we're exposed to the public. Weev's security company exposed "gaping holes". AT&T are at fault for exposing their customers information in the first place. Anybody COULD have done harm with those emails. He didn't. He used them as a fodder for public discussion about internet security. AT&T should owe him a "thank you". AT&T customers owe AT&T a boycott for being irresponsible with their information.
I think the question of AT&T having responsibility for inadequate controls is very interesting. I would like to see AT&T face some repercussions for it. Not _instead of_ weev receiving punishment, but _in addition to_.