A case that highlights the new reality in the field of cybersecurity comes from Japan, where authorities have arrested a 15-year-old student on suspicion of a large-scale cyberattack against Bandai Channel, the popular anime and tokusatsu streaming service operated by Bandai Namco Filmworks.

According to Japanese authorities, the minor allegedly exploited ChatGPT to create a specialized automation tool, which allowed him to gain unauthorized access to the platform's systems and cause an extensive disruption of services.
The case is deeply concerning, as it is yet another example of how tools Generative AI can be used not only for productive applications, but also to support illegal actions.
Bandai Channel: Thousands of accounts deleted within hours
Researchers claim that the 15-year-old, who was in the third year of high school in November 2025, managed to gain access to the Bandai Channel backend servers.
See also: Is the 'SaaSpocalypse' a myth? The real cost of software built with AI
From there, he allegedly activated an automated process that led to the deletion of 46,812 user accounts, causing serious disruption to the operation of the service.
The extent of the incident was such that Bandai Namco Filmworks was forced to temporarily suspend all Bandai Channel services in order to contain the attack, investigate the incident, and restore the security of its information systems.
Services were restored several weeks later, after additional protection measures were implemented and the infrastructure inspection was completed.
ChatGPT was used to develop the tool
According to the police investigation, the suspect used ChatGPT to create the necessary code that automated the attack. Authorities clarify that the artificial intelligence did not carry out the breach itself. Instead, it was used as a support tool for writing and improving programs that exploited system weaknesses.

The incident highlights a new challenge for cybersecurity companies. Generative AI can significantly reduce the technical knowledge required to create scripts, automations, and testing tools, allowing even less experienced users to develop more complex attacks.
Self-taught programmer since elementary school
The young man's profile is particularly interesting. According to Japanese media, he began teaching himself programming as early as the fourth grade of elementary school. Over the years, he has acquired significant knowledge of software development and familiarized himself with artificial intelligence tools that speed up code writing.
Researchers estimate that the combination of skills and modern AI tools allowed him to create a program capable of performing massive automated actions on real information systems.
See also: QuimaRAT: New Java RAT targets Windows, Linux and macOS
Personal data was also stolen
During the breach, the perpetrator also gained access to users' personal information, such as email addresses and account aliases.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Bandai Namco Filmworks said that so far there is no evidence that the data was made public or used for other forms of electronic fraud.
However, experts point out that even when no personal data is leaked, such a large-scale breach can lead to serious operational impacts, financial losses and a significant reduction in user trust.
The company announced that it is strengthening its information security management system, aiming to prevent similar incidents in the future.
There was no financial incentive
During his interrogation, the 15-year-old admitted to the charges, stating that he had no personal animosity towards the companies affected. This particular report leads authorities to the conclusion that the likely motive was not financial gain or blackmail, but the desire to demonstrate technical skills and curiosity about the capabilities of information systems.
These types of incidents are particularly common among young perpetrators, who often begin by experimenting without fully understanding the legal and operational consequences of their actions.
See also: SkillCloak: Malicious AI Skills bypass scanners

A new challenge for cybersecurity
This particular case highlights two of the biggest challenges facing the cybersecurity industry today.
On the one hand, AI tools make code generation easier and faster, significantly reducing the level of expertise required to develop automated attacks. On the other hand, online services that rely on millions of user accounts are increasingly becoming targets, as even an attack without data theft can cause severe downtime.
Experts recommend that businesses invest in stronger mechanisms for detecting suspicious behavior, limiting the number of requests an account can perform in a short period of time, multi-factor authentication (MFA), and behavioral analysis systems that can detect mass automated actions.
As artificial intelligence becomes increasingly accessible, organizations are being called upon to adapt their defense strategies to a new era, where cyberattacks do not necessarily require large teams of experts, but can be organized even by a single user with the appropriate knowledge and access to modern AI tools.
