Earlier quoted context omitted.
He knowingly manipulated their device detection system. Yes, it's true their device detection system is trivial to manipulate, but that doesn't change the legality. If a bank forgets to lock their vault, you still wouldn't want to clean them out and admit to it on your blog.
What if you just choose to change your user agent to something different because you prefer the experience? If you then get different offers as a result you can't be held liable.
On the other hand, if he had simply forgotten to change his UA back to the default (say, after doing some development work), then he couldn't possibly know that he was benefiting from the lower price, and it wouldn't be fraud at that point.
Personally, I have no problem with breaking trivial locks on otherwise non-sensitive networks. The word "fraud" usually conjures up much more serious crime.
* This is very quickly becoming a false assumption I think. Between listening to music from remote servers and watching video on my phone, I think mobile data use, especially in a vacation situation, is fast approaching that of "traditional" data use.