Japanese student launches ChatGPT-powered cyberattack against internet cafe chain
Japanese student launches ChatGPT-powered cyberattack against internet cafe chain
Occurred: January 2025
Page published: December 2025
A 17-year-old high school student from Osaka was arrested on suspicion of using a programme developed with ChatGPT to carry out a cyberattack against a local internet cafe chain.
Tokyo’s Metropolitan Police say the unnamed male student used ChatGPT to learn how to bypass the cybersecurity of Kaikatsu Frontier, which operates the popular Kaikatsu Club internet cafe chain and FiT24 fitness gym services.
He also used it to understand how to deal with any error messages that would appear while attempting unauthorised access, thereby improving his program.
Using another programme he created, the student then breached the company's server and, over three days, sent millions of unauthorised commands in order to systematically export as many customer records as possible from the company’s membership database.
Investigators allege the student obtained roughly 7.25 million sets of membership personal information, including names, addresses and phone numbers.
He was arrested for violating Japan's Prohibition of Unauthorized Computer Access Law and obstructing the operations of the targeted companies.
The student had previously been arrested in a separate credit card fraud case and is said to have strong cybersecurity skills.
According to investigative accounts, the boy is suspected of building an automated programme with help from ChatGPT, using the chatbot to get guidance on finding vulnerabilities, bypassing safeguards and handling error messages while masking his criminal intent in the prompts.
This illustrates how generative AI safety filters can be circumvented through carefully worded queries, highlighting limitations on how guardrails work and how easily skilled users can route around them.
The arrest adds to growing evidence that generative AI can significantly lower the barrier to conducting sophisticated cyberattacks, especially for technically capable young people seeking a challenge or notoriety.
For customers: For affected customers, the incident creates a long-term risk of privacy invasion, phishing, identity fraud and social engineering.
For industry: The case may erode trust in everyday services like internet cafes and fitness clubs that collect extensive personal information but may not visibly demonstrate robust security or clear redress mechanisms when breaches occur.
Developer: OpenAI
Country: Japan
Sector: Retail
Purpose: Plan cyberattack
Technology: Generative AI
Issue: Privacy; Security
https://mainichi.jp/english/articles/20251204/p2g/00m/0na/021000c
https://www.japantimes.co.jp/news/2025/12/04/japan/crime-legal/police-arrest-cyberattack-net-cafe/
https://japannews.yomiuri.co.jp/society/crime-courts/20251204-296346/
AIAAIC Repository ID: AIAAIC2150