Advertisement

Japan arrests 15-year-old for allegedly using ChatGPT in cyberattack: Here's what happened

Japanese police have arrested a 15-year-old student accused of using ChatGPT to help carry out a cyberattack that disrupted an anime streaming platform. The case is being closely watched because it highlights how generative AI can be used to simplify sophisticated cybercrime, particularly by individuals with limited technical experience.

Advertisement
ChatGPT (Photo: Reuters)
ChatGPT (Photo: Reuters)
FP Tech Desk|Jul 10, 2026, 14:13:20 IST

A cybercrime case involving a 15-year-old student in Japan has reignited debate over the role of generative artificial intelligence in online attacks. The teenager has been arrested after allegedly using ChatGPT to help develop software that deleted tens of thousands of user accounts from an anime streaming service, causing prolonged disruption and financial losses for the company.

Advertisement

While the investigation centres on one individual, authorities believe the incident illustrates a wider challenge facing governments and technology companies. As AI tools become increasingly capable of writing and refining code, cybersecurity experts have warned that they could also lower the technical barriers for people seeking to launch cyberattacks.

Here's what happened and why the case matters.

techMore from Tech

What is the teenager accused of doing?

According to Tokyo's Metropolitan Police Department, the high school student from Tokorozawa, near Tokyo, allegedly sent fraudulent commands to the servers of Bandai Namco Filmworks on 4 November 2025. The company, a subsidiary of Bandai Namco Holdings, operates the Bandai Channel anime streaming platform.

Investigators say the attack resulted in the unauthorised deletion of 46,812 user accounts. Those accounts were removed without the knowledge or permission of their owners, forcing the company to halt services while it attempted to recover its systems.

Advertisement

Police have charged the teenager with fraudulent obstruction of business, alleging that the attack was carried out deliberately and continued even after the company introduced countermeasures. Investigators say the student repeatedly changed his IP address—around 30 times—to bypass restrictions and continue sending malicious commands.

The disruption lasted for more than a month, during which Bandai Namco Filmworks suspended parts of its service and refunded affected subscribers.

How did ChatGPT become part of the investigation?

One aspect that has attracted particular attention is the student's own account of how he developed the attack.

During questioning, he told investigators that he initially wrote the code himself but later relied on ChatGPT to improve it.

"I created the source code for the withdrawal process myself. Since the processing was taking a long time, I asked ChatGPT and completed it in a different programming language," he told investigators, according to The Asahi Shimbun.

Police say the teenager claimed he did not target the company out of personal resentment. Instead, he reportedly chose the streaming platform because it had a large number of user accounts that he believed he could access.

Advertisement

The student had reportedly been teaching himself programming since primary school and told investigators he enjoyed analysing network communications. Authorities had first arrested him in June on suspicion of logging into the service using another subscriber's account, an investigation that later uncovered the larger attack.

Why is this case significant?

Although cybercriminals have long used automated tools, investigators believe this could be among the first cases in Japan where generative AI has been directly linked to the development of software used in a cyberattack.

The case does not suggest that ChatGPT independently carried out the attack. Instead, police allege that the AI chatbot helped refine existing code and translate it into another programming language, making the software more efficient.

The incident has renewed concerns about how accessible sophisticated programming assistance has become. Generative AI systems can explain coding concepts, identify errors and rewrite software in different languages, making them valuable productivity tools for developers. At the same time, cybersecurity experts have warned that such capabilities can also be misused by individuals attempting to build malicious software.

The cyberattack also had wider consequences beyond the deleted accounts. The month after the incident, Bandai Namco Filmworks disclosed that information associated with as many as 1.36 million accounts—including email addresses, account balances and payment details—might have been exposed. The company said it had found no evidence that the data had subsequently been published or exploited.

In a statement carried by Japanese media, the company said, "We take this situation very seriously and will continue to conduct regular checks and strive to prevent any recurrence."

Following the arrest, a senior investigator with Tokyo's Metropolitan Police Department also warned against treating online offences as harmless experiments.

"Cyberspace is highly anonymous, and people may be tempted to commit crimes casually, but these actions can lead to grave consequences," the investigator said.

As governments continue to grapple with the rapid growth of generative AI, the case is likely to become an important reference point in discussions about how AI tools should be governed, monitored and safeguarded against criminal misuse.

Handpicked stories, in your inbox
Global stories. Indian perspective. Zero noise.
No Spam. Unsubscribe Any Time.
First Published:Jul 10, 2026, 14:13:20 IST
Advertisement
Advertisement
Advertisement
Advertisement
Up Next