Like the man or not, it's pretty easy for any technically savvy individual to see your information was leaked by AT&T, not this guy. He just pointed out what was going on. And this is hardly an "exploit" so much as stumbling across a glaring bug that he did report to a news organization, not leverage for profit.
Does this really deserve a sentence that will effectively ruin a mans life (beyond the damage that has allegedly already been done)? Have you so much as stopped doing business with AT&T?
I think the public has some responsibility to demand the justice system be fair for all individuals without bias, not just the ones we like. It's probably also worth asking what is being done about companies, like AT&T in this case, that are carelessly releasing said private information to the public while we are actively prosecuting people who stumble across it.
And if your intent is to sell the data, you don't use your real name when you get a media organization to write up the security hole.