A Teenager Used ChatGPT to Build a Cyberattack Tool and Steal Seven Million Records
What happened
In January 2025, a 17-year-old high school student from Osaka was arrested on suspicion of breaching the servers of a Japanese internet cafe chain and extracting roughly 7.25 million sets of customer membership data, including names, addresses, and phone numbers. Tokyo's Metropolitan Police allege the student built the attack tool himself, with substantial guidance from a generative AI chatbot he consulted at each stage of development.
The student's approach, according to investigators, was to use ChatGPT to get guidance on locating system vulnerabilities, bypassing security safeguards, and handling the error messages that surfaced while testing unauthorized access. He masked his intent in how he phrased his prompts. Once the tool was functional, he used a second program he had built to breach the company's server and spent three days issuing millions of unauthorized commands to systematically pull customer records from the membership database.
The scale of the exfiltration, 7.25 million records across three days, reflects how much leverage the AI-assisted development gave the attacker. A manual effort against the same system would have been slower, noisier, and more likely to trigger a detection before completion. By offloading the iterative problem-solving to a chatbot, the student compressed a development timeline that would ordinarily require specialized knowledge and repeated trial and error into something a motivated teenager could move through over a short period. He was arrested under Japan's Prohibition of Unauthorized Computer Access Law and for obstructing the operations of targeted companies. Investigators note he had already been arrested in a separate credit card fraud case and had strong cybersecurity skills going in.
The arrest adds to a growing body of cases in which generative AI has lowered the entry barrier for sophisticated attacks, especially for technically capable individuals who previously lacked the domain expertise to move from intent to execution. Internet cafes and fitness clubs collect extensive personal data on their customers but rarely demonstrate the kind of visible security posture that might deter an attempt. For the millions of people whose records were taken, the long-term exposure includes phishing, identity fraud, and social engineering, with no practical way to undo the breach.
What the case also makes plain is how little accountability infrastructure surrounds an AI tool's role in constructing an attack. The chatbot produced no log investigators could subpoena, no audit trail linking specific prompts to specific guidance, and no record tying the AI session to the eventual breach. A provable record of what a system did, which queries it answered and what guidance it provided, would hand investigators a starting point that currently does not exist, forcing reconstructions from endpoint evidence alone long after the damage is done.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.