OpenAI has disrupted a Cambodia-based scam operation that leveraged its ChatGPT AI chatbot to facilitate a wide range of fraudulent schemes, including investment, romance, gambling, and law enforcement impersonation scams. The company banned a coordinated network of ChatGPT accounts originating from Southeast Asia, operating from Poipet, a region known for scam compounds and human trafficking.
The threat actors used OpenAI’s models to create fake online personas, generate and translate messages, produce promotional content for fraudulent schemes, and assist with day-to-day administrative tasks. Promotional content included social media ads for ‘chatter’ jobs in Poipet targeting users in Bangladesh and India, offering salaries, bonuses, and other incentives. Some accounts also used the AI tool for administrative work, such as drafting internal announcements and documenting employee debts and immigration status.
OpenAI investigated the operation in partnership with Meta-owned WhatsApp. The network conducted various scams in parallel, blending techniques to increase success. They used dating personas to build trust before luring victims into fraudulent cryptocurrency and gold trading investments, engaged in romantic conversations with synthetic identities, posed as online gambling platforms offering fake bonuses, and impersonated law enforcement to demand fines for fabricated offenses. The network created fake dating profiles, fictitious investment experts, and fraudulent law enforcement personas, and generated images of forged documents, including passports and legal notices.
The attack chain follows a three-step approach called ‘ping-zing-sting’: initial outreach on messaging platforms like WhatsApp and Telegram, trust-building, then instructing victims to make deposits or pay fees. Victims were provided fake screenshots as proof of payment. Some accounts generated content consistent with human trafficking and forced labor associated with organized crime groups in East Asia. The full scale of financial losses is unknown, but the operation may have interacted with hundreds of targets, with individual victims losing thousands of dollars.
CVEs: CVE-2026-50522
Original source: thehackernews.com