A 17-year-old Japanese high school student used AI-generated code to breach Kaikatsu Frontier's servers 7.24 million times, potentially exposing personal information of 7.3 million customers.
In January 2025, Kaikatsu Frontier Inc., operator of Kaikatsu Club internet cafes and FiT24 fitness gyms in Japan, suffered a cyberattack that potentially compromised personal information of 7.29 million customers. A 17-year-old high school student from Osaka was arrested on suspicion of breaching the company's servers using a program generated by conversational artificial intelligence. The student allegedly sent unauthorized commands to Kaikatsu Frontier's server approximately 7.24 million times to export personal data, thereby obstructing business operations. The attack was detected on January 18, 2025, when the company identified unauthorized access and immediately disconnected the servers from the network. The potentially compromised information included names, addresses, phone numbers, birthdates, member numbers, and other customer data spanning from 2015 to 2025 for various service members. The student had concealed his true intentions when prompting the AI to generate the malicious code, as AI services generally do not create content for criminal purposes. The same individual had previously been arrested in November for allegedly using stolen credit card information to purchase Pokemon cards online.
Domain classification, causal taxonomy, severity scores, and national security assessments were LLM-classified and may contain errors.
Using AI systems to gain a personal advantage over others such as through cheating, fraud, scams, blackmail or targeted manipulation of beliefs or behavior. Examples include AI-facilitated plagiarism for research or education, impersonating a trusted or fake individual for illegitimate financial benefit, or creating humiliating or sexual imagery.
Human
Due to a decision or action made by humans
Intentional
Due to an expected outcome from pursuing a goal
Post-deployment
Occurring after the AI model has been trained and deployed