Tokyo Metropolitan Police have arrested a 15-year-old high school student for using ChatGPT to write a program used in a cyberattack on Bandai Namco Filmworks’ Bandai Channel streaming service that disrupted the platform and led to the illegal cancellation of 46,812 user accounts.

According to Japanese media reports, investigators believe the teenager exploited a vulnerability in the anime streaming platform in November 2025 and developed a program with the help of AI that automated unauthorised access to member accounts, leading to a charge of fraudulent obstruction of business.

The teenager wrote the source code for the account withdrawal process himself before turning to ChatGPT to speed up the work by rewriting it in another programming language.

The cyberattack disrupted Bandai Channel from November 6, with services fully restored only in December after repairs to its systems. Investigators alleged the breach began two days earlier, when the teenager sent fraudulent commands to the platform’s servers after discovering the security flaw.

Although Bandai reported the incident to police and the company blocked his access, investigators alleged the teenager changed his IP address about 30 times in an attempt to continue sending malicious commands.

The accused was in junior high school when it took place and had already been arrested in June this year over separate computer-related offences. Investigators said he had been teaching himself programming since elementary school.

During questioning, the teenager reportedly acknowledged the allegations but said he had no personal grudge against Bandai Namco Filmworks. Investigators said he claimed he targeted the platform because he found numerous user accounts he could access.

Bandai Namco Filmworks contacted affected users after discovering the breach, warning them about phishing and impersonation emails. It also asked customers whose memberships had been cancelled to register again and said it would refund subscription fees charged during the service disruption.

The company said it had found no indication that any customer data had been circulated online or used for malicious purposes. It added that it would continue tightening security measures to guard against future incidents.