Japanese police arrested a 15-year-old high school student from Saitama Prefecture for allegedly carrying out a sustained cyberattack against Bandai Channel, the anime streaming service operated by Bandai Namco Filmworks. Investigators said the suspect exploited a server-side flaw, analyzed network traffic, and used a custom malicious program reportedly developed with assistance from ChatGPT to gain unauthorized backend access, cancel 46,812 member registrations, and collect member data including email addresses and nicknames.
The attack disrupted Bandai Channel in November 2025 and forced the company to suspend the service for more than a month while it repaired systems, refunded subscribers, and implemented stronger security measures before restoring operations in December. Police said the teenager continued the activity after being blocked by repeatedly changing IP addresses, and later identified him through communication record analysis; the suspect reportedly admitted the allegations and said he acted out of technical curiosity rather than any grudge, while the company said it had not confirmed any public leak of personal data or secondary fraud.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Japanese police arrested a 15-year-old student from Tokorozawa City, Saitama Prefecture, in connection with the Bandai Channel cyberattack. Reports said the suspect admitted the allegations and told investigators he acted out of technical curiosity rather than a grudge.
In December 2025, Bandai Channel services were restored after Bandai Namco Filmworks implemented enhanced security measures. The company said it had not confirmed any public leak of personal data or secondary fraud.
The cyberattack forced Bandai Namco Filmworks to suspend all Bandai Channel services in November 2025. According to reporting, the platform remained offline for over a month while systems were repaired and subscribers were refunded.
During the November 2025 attack, fraudulent cancellation requests allegedly caused 46,812 member registrations to be canceled and member information such as email addresses and nicknames to be harvested. The disruption affected tens of thousands of subscribers.
In November 2025, a 15-year-old suspect allegedly exploited a server-side flaw and used a custom malicious program to gain unauthorized access to Bandai Channel systems. Investigators said the activity included repeated access attempts using changing IP addresses after initial blocking.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcetherecord.media
Open sourcedarkwebinformer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.