I have pretty mixed feelings on this. On the one hand, I agree that the researcher's actions (particularly the use of a false identity) were inappropriate. I am hesitant to engage in "victim blaming" by calling the targets of the email naive. But I hope this has been a learning experience for everyone, as it seems to have revealed a lot of knowledge gaps that were surprising to me.
I am not at all surprised that it was not subject to IRB review, but only because I've had a bit of involvement in the IRB process before and know that the specific legal mandates that drive IRBs (45 CFR 46) have a surprisingly narrow definition of human subject research that is driven primarily towards medical interventions, so generally speaking any research that consists of just asking questions and then anonymizing the results for reporting gets waved past IRBs (45 CFR 46.104). You might disagree with the situation (there's plenty of reasons to) but it's the law of the land. IRBs were developed pretty specifically in response to a spate of incidents in the mid-century, but especially the Tuskegee trials, involving non-consensual drug and toxin trials. The IRB process is directly designed to address these kinds of medical research, and so IRBs I've dealt with are not even very interested in looking at proposals coming from departments other than life sciences. The idea that IRBs are a general-purpose ethics review seems to be a pretty recent idea and it's not something the IRBs themselves are that into, at least from my experience hearing professors gripe about having to go through a stack of pre-reviews for information assurance studies on the off chance they qualify as human subject research.
On the other hand, though, I operate several websites for small organizations, admittedly in a politics and public policy-adjacent space, and receive emails of this type as a matter of course. I'd be surprised if there are many people operating websites that get a meaningful amount of traffic that don't get an email of this type from time to time. It's sort of background noise if you're doing anything that's of much public interest. In some of these situations I benefit from having retained legal counsel that probably wouldn't even bother to bill for this kind of thing, but it would still be a rare situation that I referred such an email to counsel unless it was something about a more obscure corner of city political financing regulations, which I have gotten once before.
The "legal threat" here honestly doesn't read to me as much of a threat. Part of this is because in my hobby work I write emails very much like this one on a weekly basis... mostly citing FOIA or similar state sunshine/open records/open meetings laws. Many guides on transparency laws coming from this same community clearly advocate a similar sentence citing the response deadline, and I wouldn't be surprised if this researcher copied and pasted that from such a "consumer rights" guide. It's considered a best practice to state the deadline and citation with this kind of request. There are basically two reasons for this: first, some people, especially smaller organizations, may be totally unaware of the deadline and you will be telling them about it for the first time. They may not believe you on it if you don't provide some sort of backing. The second is that there's a perception (from my experience I'm skeptical this is frequently true but I'm sure it is occasionally) that especially federal offices may be aware of the deadline but feel comfortable ignoring it if they don't think the requester knows. So providing the deadline and citation is sort of a "savvy customer" indication that encourages them to at least issue an extension letter on time (even then it's very common, even before COVID but especially now, for federal agencies to run past the deadline without any response. Oddly, state and local agencies are usually much better about this).
Another part of why I have a hard time taking it as a threat is because it is the first in a rather long chain of actions that would lead to legal action. It does indicate that the requester is aware of the law but it's quite a few steps from the requester's intent to file a lawsuit. Most people that include a line like that never even bother to follow up with a nag when the deadline passes. What was in the email is basically a "I copied and pasted this from an online howto" level of effort, and there's a pretty big ramp from there to filing a lawsuit (especially from a far away place). Really, in my experience, people who are a serious legal risk (i.e. lawyers and people who use them) cite statute less often than slightly crazy internet randoms do.
So I suppose what I mean to say, is that I feel bad for the people who were alarmed by this, but I hope it has been a learning experience: when you operate a website, you are putting yourself out in public and exposing yourself to both legal obligations and dealing with random people that have weird ideas about your legal obligations (there tend to be more of the latter than the former). There are a lot of risks and responsibilities entailed in running a website, most of them fairly minor, and this kind of thing is one of them... just something you have to deal with when you make the decision to be a public entity.
Or maybe a better takeaway is this: if you get at all involved in politics, government, civil rights, or the public sector in general you will get a lot of stuff like this (and some of it will actually require action, but usually not especially difficult action). One result of increasing online privacy concerns is that just operating a website is starting to enter the civil rights realm, so I suppose over time every website will get more of this.