Earlier quoted context omitted.
Defeating access control by using credentials that aren't yours is fraud. Like, if you found a company badge laying around, go to that office and flash the badge to the security guard and go in. You've committed fraud by tricking the guard into thinking you're authorized to enter when you weren't.
I see, thanks. No credentials involved here, though.
API documented on the website under a section called “For Developers”? Probably, yes. API reverse engineered by intercepting requests? Probably not.
Note that the blog was taken down before I could read it myself.