TOKYO (TR) – The landscape of cybercrime is undergoing a radical shift. A hacker in his 30s has come forward to detail how he weaponized free artificial intelligence to rake in approximately 1 billion yen over the past four years through deepfakes, phishing and corporate extortion.
Speaking to Spa! (July 21-28) under the pseudonym “Mr. X,” the hacker explained that the proliferation of high-performance Large Language Models (LLMs) has essentially eliminated the need for specialized coding knowledge in the cyber underworld.
“AI handles everything from drafting phishing emails and gathering intelligence to installing ransomware,” X said. “I don’t even need paid versions. Chinese-made free AI software does the job perfectly, so I don’t even have to leave a billing trail.”

Scraping business platforms
According to X, blasting out 100,000 targeted phishing emails a day requires little more than the push of a button. However, his most lucrative schemes involve sophisticated impersonation. By scraping business platforms like LinkedIn, X targets specific corporate executives. He then uses AI-generated deepfake audio and video to impersonate presidents or managers, tricking subordinates into wiring large sums of money.
X also profits by selling these customized deepfake fraud tools on the dark web for between 1 million and 3 million yen per package.
His primary targets are startups or companies run by authoritarian presidents. “These companies have cash, and the power to transfer funds is concentrated in a few hands, making them easy bait,” X explained.
“Jailbreaking”
To demonstrate the terrifying ease of the crime, X recently targeted the Japanese subsidiary of a company simply “for fun.” By impersonating the president, he successfully duped the staff into wiring him 3.3 million yen in an instant.
While most commercial AI tools have ethical filters to prevent criminal use, X easily bypasses them through a process known as “jailbreaking” — manipulating the prompts to strip the AI of its ethical guardrails and force it to write malicious code.
To protect his illicit 1-billion-yen empire, X conducts all transactions in untraceable cryptocurrency and has installed a “dead man’s switch” on his computer. “I’ve created a manual for when I get arrested. If I don’t log into my PC for 12 hours, a system automatically erases all data,” he boasted.
Japanese companies as “easy prey”
Cybersecurity experts warn that Japanese companies are uniquely vulnerable to this new wave of AI-driven crime.
Tomoyuki Fujii, an executive at security consulting firm LRM, says AI acts as a free, native-level Japanese teacher, voice actor, and video editor for foreign attackers.
“In the past, unnatural Japanese was the first red flag of a scam. Japanese companies relied on that, so they have absolutely no immunity now that AI has breached that defense,” Fujii said.
Hackers now routinely use psychological tactics, posing as a CEO in an email or fake web-conference, telling an accountant that an urgent wire transfer is “top-secret,” effectively isolating the victim in a closed chat room to prevent them from verifying the request with colleagues.
Weaknesses in Japanese corporate culture
Fujii points out three fatal weaknesses in Japanese corporate culture: the sudden loss of the language barrier, the concentration of financial authority in specific individuals due to lifetime employment, and a woefully low investment in IT security compared to overseas competitors.
Furthermore, hackers are now utilizing “reverse scams”—contacting companies terrified of deepfakes to sell them fake AI-security software, only to hack their internal systems once the software is installed.
“You cannot rely on technology alone to fight a technologically armed attacker,” Fujii warned. “Companies must implement human countermeasures. This means requiring third-party verification through a separate channel before any money is sent, holding in-person meetings for important decisions, or establishing secret passwords for financial approvals.”




