Japanese student launches ChatGPT-powered cyberattack against internet cafe chain
A 17-year-old high school student from Osaka was arrested on suspicion of using a programme developed with ChatGPT to carry out a cyberattack against a local internet cafe chain. What happened Tokyo’s Metropolitan Police say the unnamed male student used ChatGPT to learn how to bypass the cybersecurity of Kaikatsu Frontier, which operates the popular Kaikatsu Club internet cafe chain and FiT24 fitness gym services. He also used it to understand how to deal with any error messages that would appear while attempting unauthorised access, thereby improving his program. Using another programme he created, the student then breached the company's server and, over three days, sent millions of unauthorised commands in order to systematically export as many customer records as possible from the company’s membership database. Investigators allege the student obtained roughly 7.25 million sets of membership personal information, including names, addresses and phone numbers. He was arrested for violating Japan's Prohibition of Unauthorized Computer Access Law and obstructing the operations of the targeted companies. The student had previously been arrested in a separate credit card fraud case and is said to have strong cybersecurity skills. Why it happened According to investigative accounts, the boy is suspected of building an automated programme with help from ChatGPT, using the chatbot to get guidance on finding vulnerabilities, bypassing safeguards and handling error messages while masking his criminal intent in the prompts. This illustrates how generative AI safety filters can be circumvented through carefully worded queries, highlighting limitations on how guardrails work and how easily skilled users can route around them. What it means T he arrest adds to growing evidence that generative AI can significantly lower the barrier to conducting sophisticated cyberattacks, especially for technically capable young people seeking a challenge or notoriety. For customers: For affected customers, the incident creates a long-term risk of privacy invasion, phishing, identity fraud and social engineering. For industry: The case may erode trust in everyday services like internet cafes and fitness clubs that collect extensive personal information but may not visibly demonstrate robust security or clear redress mechanisms when breaches occur. System 🤖 ChatGPT Developer: OpenAI Country: Japan Sector: Retail Purpose: Plan cyber attack Technology: Generative AI Issue: Privacy; Security
- Date it happened
- 2025-01-01
- Organisation involved
- Japanese student
- Product, system or model
- ChatGPT
This incident was imported from AIAAIC and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.
This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.