It's about time some company was prosecuted under CFAA for this kind of abuse. This should easily fit the legal definition of "intentional unauthorized computer access."
But we all know, the law is enforced aginst regular people, not corporations. Are corporations ever prosecuted for invoking something on a user's computer without their authorization?