The case is considered one of Japan’s first criminal investigations involving the alleged use of generative AI to assist in a cyberattack.
Thousands of Accounts Deleted
According to investigators, the suspect targeted Bandai Channel, operated by Bandai Namco Filmworks, by sending fraudulent commands to the company’s servers, forcing the deletion of 46,812 user accounts without the owners’ consent.
The attack disrupted the service for more than a month and required the company to issue refunds to affected subscribers.
ChatGPT Used to Refine the Code
Police said the teenager admitted writing the initial source code himself before using ChatGPT to refine it and convert it into another programming language to improve its functionality.
He reportedly told investigators that he had no personal grudge against the company and selected it because of the large number of user accounts available on the platform.
Growing Cybersecurity Concerns
Authorities said the suspect repeatedly changed his IP address to bypass security measures after being blocked by the company.
Bandai Namco Filmworks later disclosed that personal information linked to as many as 1.36 million accounts, including email addresses, account balances, and payment methods, may have been affected, although the company said it found no evidence that the data had been publicly leaked or maliciously exploited.
The incident highlights growing concerns about how generative AI tools can be misused to lower the technical barriers to cybercrime while underscoring the need for stronger cybersecurity safeguards.
