TechNadu • 19h
Bandai Namco: LLM-Assisted Mass Subscription Cancellation Attack
An attacker utilized ChatGPT to develop automation scripts that exploited an authorization bypass or Insecure Direct Object Reference (IDOR) vulnerability within the Bandai Namco anime streaming service's subscription management endpoints. By manipulating the logic governing account cancellations, the perpetrator successfully automated the fraudulent cancellation of 46,812 user accounts. This incident demonstrates the operationalization of Large Language Models (LLMs) by low-skill threat actors to generate functional exploit code, effectively scaling an application-layer vulnerability into a mass-scale service disruption.