New-ZZZ
RU / EN
Security 2 August 2026

OpenAI Disrupts Cambodia-Based Multi-Scam Network

N
New-ZZZ desk
· 6 days ago

OpenAI says it disrupted a coordinated scam network that very likely originated in Cambodia and was probably operating in or around Poipet, a city in Banteay Meanchey province repeatedly associated in public reporting with online scam compounds and human-trafficking operations. The investigation began after WhatsApp shared a lead, and OpenAI subsequently passed additional threat indicators to industry partners and relevant authorities. The company banned the network’s ChatGPT accounts after determining that they were being used to support a broad criminal operation rather than one isolated fraud campaign.

The network used ChatGPT across several stages of its activity: building fake identities, writing and translating messages to prospective victims, producing promotional material, fabricating supporting visuals, and handling routine internal administration. This breadth is important because the operation did not specialize in a single deception. Its participants shifted among investment fraud, romance scams, bogus gambling offers, and impersonation of law-enforcement agencies, selecting or combining narratives according to what appeared most likely to manipulate each target.

One recurring approach began with a fabricated dating identity. Operators cultivated familiarity through prolonged personal or romantic conversations and then introduced supposedly profitable opportunities involving cryptocurrency or spot gold trading. Other accounts maintained romance-focused deceptions without the same investment framing. A separate group posed as representatives of online gambling platforms, promising bonuses or winnings that did not exist. Some scammers adopted the identity of law-enforcement authorities and falsely accused targets of serious crimes, telling them that fines had to be paid to avoid further consequences.

Despite these different stories, the accounts followed a consistent operational model. They researched material for dating profiles, created fictitious investment specialists, managed false social-media personas, and developed fraudulent police or legal identities. ChatGPT was used to generate or translate conversations for services including WhatsApp and Telegram, allowing operators to communicate with victims across language barriers. The network also created images representing forged passports, legal notices, stock-purchase confirmations, cryptocurrency services, and gambling-platform interfaces. OpenAI highlighted both a fake cryptocurrency trading interface and an AI-generated promotional image for a bogus investment scheme as examples of the material produced within the network.

OpenAI describes the scammers’ interaction pattern as the “ping, zing, and sting.” The ping was the initial outreach: operators contacted targets through messaging platforms, prepared social-media posts, and assembled credible-looking background material for their invented personas. The zing was the emotional manipulation used to deepen engagement. Messages promised guaranteed profits or supposedly risk-free investments, used romantic language to create attachment, demanded secrecy, or imposed artificial urgency by claiming that a bonus would soon expire.

The sting was the point at which the operation attempted to extract money or sensitive financial evidence. Victims were instructed to deposit funds to unlock alleged rewards, pay activation charges, or settle fabricated criminal fines. Operators then requested screenshots of transfers or account details as proof that payment had been made. Although the surface story could involve romance, investing, gambling, or criminal accusations, the underlying sequence remained the same: establish contact, manufacture trust or fear, and convert that pressure into a payment.

The network also relied on ChatGPT for work that appeared to support the organization internally. Users drafted announcements, translated communications among staff, and documented issues apparently involving recruitment, immigration status, working conditions, and employee discipline. These administrative uses resemble behavior OpenAI says it has observed in previously disrupted scam networks, where AI tools are employed not only in victim-facing messages but also in the ordinary management of the operation.

Some generated content raised an additional and more complex concern. OpenAI observed indications potentially connected to human trafficking or forced criminal activity, including the creation of social-media advertisements for “chatter” jobs in Poipet. The company relates these signals to extensive public reporting about Southeast Asian criminal groups that recruit people with promises of legitimate employment, then trap them through coercion and debt bondage and compel them to participate in online scams.

OpenAI stresses that it cannot independently establish the circumstances of every person involved. That qualification matters because individuals sending fraudulent messages may not all occupy the same role: some may be willing participants, while others may themselves be exploited workers. The case therefore shows both how generative AI can increase the efficiency and linguistic reach of organized fraud and how scam compounds may intersect with coercion, trafficking, and forced labor. OpenAI’s response combined account bans with information sharing, but the reported activity also demonstrates why disruption requires cooperation among AI providers, messaging services, other technology companies, and public authorities.

Why it matters

  • The case shows how organized criminal networks can use generative AI to operate several scam formats, cross language barriers, and create convincing fake material at scale.
  • Indicators of trafficking and forced labor suggest that some people conducting the scams may also be victims of coercion.
  • The investigation demonstrates the importance of sharing threat signals among AI companies, messaging platforms, and authorities.

Key facts

  • OpenAI banned a coordinated network of ChatGPT accounts likely originating near Poipet, Cambodia, after receiving a lead from WhatsApp.
  • The network supported investment, romance, gambling, and law-enforcement impersonation scams, sometimes combining several techniques against one target.
  • ChatGPT was used to build fake personas, translate victim conversations, create promotional content and forged-document images, and assist with internal administration.
  • Victims were pressured to make deposits, pay activation fees or fictitious fines, and submit transfer screenshots or account information.
  • Some generated content, including advertisements for “chatter” jobs in Poipet, suggested possible links to human trafficking or forced labor.

/ related