Legally, bypassing security controls, using credentials that are not yours, and accessing data without authorization is a crime[1]. I see no indication that this blog post was authorized. Others should not consider this blog post as a good approach.
Look instead to bug bounty programs and stay in-scope. Often that means creating your own account and avoiding other customer's data.
While it doesn't make a good blog post, I still emphasize that the author should have reported the leaked credentials and stopped.
[1] varies by jurisdiction, I'm not a lawyer, etc.