Artificial intelligence is making software development faster than ever. But the same technology is also lowering the barrier to carrying out sophisticated cyberattacks.
A recent case from Japan has become one of the clearest examples of this growing challenge. Japanese police have arrested a 15-year-old middle school student on suspicion of carrying out a cyberattack against Bandai Channel, an anime streaming platform. According to investigators, the teenager discovered a vulnerability in the company’s system and used ChatGPT to help write a program that automatically canceled 46,812 user subscriptions. The attack severely disrupted the platform and raised concerns over a potential data breach affecting 1.37 million user accounts.
The incident dates back to November 2025. Investigators say the student first analyzed Bandai Channel’s network traffic and identified a security flaw. He then used ChatGPT to help generate code for an automated tool capable of canceling subscriptions on a massive scale. Within hours, tens of thousands of user subscriptions had been canceled, forcing the streaming service into prolonged disruption.
To avoid detection, the teenager reportedly changed his IP address around 30 times after being blocked by the company. Digital forensic evidence ultimately allowed authorities to identify and arrest him months later.
The cyberattack forced Bandai Channel to suspend parts of its service while engineers worked to restore operations. The company later announced that personal information—including email addresses—belonging to as many as 1.366 million users may have been exposed during the incident. Although the platform eventually resumed normal operations, the attack highlighted how damaging a single vulnerability can become when combined with AI-assisted automation.
The case has reignited debate over AI’s role in cybersecurity. According to investigators, the teenager had been teaching himself programming since elementary school and personally discovered the system vulnerability. ChatGPT was not responsible for planning or executing the attack independently—it was used as a coding assistant to speed up software development.
This distinction is important. AI did not create the malicious intent. Instead, it significantly reduced the time and technical effort required to transform an idea into a working attack tool.
Generative AI is rapidly increasing developer productivity worldwide. At the same time, it is also making advanced programming capabilities accessible to a much broader audience—including individuals with malicious intentions.
The Bandai Channel incident demonstrates that cybersecurity is entering a new era. Companies are no longer defending only against experienced hackers; they must also prepare for attackers empowered by increasingly capable AI tools. As AI continues to evolve, the competitive advantage in cybersecurity will depend less on writing code and more on identifying and fixing vulnerabilities before they can be exploited.
Source: DigiTech














