Yea, I don't understand the response to him here. You can just tell the random student who wants the keys to the student database "no" and go about your day.
Victim blaming is not cool. These types of over-the-top legal threats in response to good-faith engagement are extremely common and it's why bug bounties have safe harbor protections.
No, I do. It was an informal usage; they were requesting access to an internal web service and universities don't give that out to every student who asks.