Back to Feed
Threat IntelligenceAug 5, 2026

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

OpenAI disrupted a Cambodia-based scam network using ChatGPT for investment, romance, and impersonation schemes.

Summary

OpenAI has shut down a large scam operation based in Poipet, Cambodia, that leveraged ChatGPT to facilitate various fraudulent activities. The network used the AI chatbot to create fake personas, generate scam messages, and produce promotional content for investment, romance, gambling, and law enforcement impersonation schemes. The operation also involved recruiting individuals with false job promises, potentially leading to human trafficking.

Full text

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes Ravie LakshmananAug 05, 2026Cybercrime / Artificial Intelligence OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a region with extensive ties to scam compounds and human trafficking in the past. The cluster of accounts is said to have used OpenAI's models to create and support the operation of fake online personas, generate and translate messages sent to scam targets, create promotional content for their fraudulent schemes, and assist with day-to-day activities. The promotional content included creating social media advertisements for "chatter" jobs in Poipet specifically targeting users in Bangladesh and India that promised a base salary of $800 (and a bonus of $100 for "full attendance"), along with flight tickets, free accommodation, meals, 1-year Cambodia visas, and work permits. A subset of these accounts have also been found to leverage the AI tool for administrative work, such as drafting internal announcements, translating messages between staff, and documenting employee debts, salary deductions, fines, loan repayments, visa overstays, work permits, immigration status, and recruitment incentives. The AI upstart said it investigated the operation in partnership with Meta-owned WhatsApp. "The operation illustrates an important reality about modern scam networks: organized criminal groups rarely restrict themselves to a single type of scam," OpenAI said. "Instead, they opportunistically employ whatever narratives, personas, and tactics they think will be most effective to deceive victims." The threat actors behind the network conducted various types of scams in parallel, blending techniques from different schemes to increase the likelihood of success of their illicit activities. Besides using dating personas to build trust before trapping victims into fraudulent investment opportunities involving cryptocurrencies and spot gold trading, the actors engaged in extended romantic conversations with targets using synthetic identities or posing as representatives of online gambling platforms that purported to offer fake bonuses and winnings. Other users that are part of the cluster impersonated law enforcement agencies to induce a false sense of urgency and inform targets they needed to pay fines for committing serious criminal offenses. To pull these off, the network created and operated fake dating profiles, fictitious investment experts, and fraudulent law enforcement personas, while also generating images of forged documents, including passports, as well as legal notices, stock-purchase confirmations, and gambling platform interfaces. The attack chain, per OpenAI, follows a three-step approach called ping-zing-sting, where the scammers undertake initial outreach on messaging platforms like WhatsApp and Telegram and engage in a trust-building exercise, before instructing victims to make deposits, pay activation fees, or settle non-existent fines. The targets are then provided fake screenshots of transfers or account information as proof of payment. Some accounts in the network generated content that is consistent with human trafficking and forced labor associated with organized crime groups in East Asia. The threat actors are known to recruit people with false promises of lucrative jobs, only to confiscate their passports and force them to work in slave-like conditions. "The full scale of financial losses associated with the network is unknown, but based on the scammers' own communications, the operation may have interacted with hundreds of targets across multiple scam types," OpenAI said. "User conversations referenced individual victims losing thousands of dollars, although we are unable to independently verify those claims." The development signals how threat actors are developing AI-augmented offensive capabilities that enable them to dramatically increase the speed and scale of their campaigns, even as the frontier models themselves have been caught targeting real systems and individuals during Capture-the-Flag (CTF)-style cyber evaluations. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  artificial intelligence, cryptocurrency, Cybercrime, Financial Fraud, Human Trafficking, Impersonation, Messaging Security, Online Scam, Romance scam, Social Engineering ⚡ Top Stories This Week New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable ⭐ Featured Resources [Webinar] How Militaries Can Trust the Data Behind Autonomous Missions Download the 5-Step Action Plan for AI-Speed Exploitation Get the Checklist for Gaining Control of AI Use Across Your Organization Get the 2026 CISO Benchmark Report Based on 600 Security Leaders

Entities

ChatGPT (product)OpenAI (vendor)Artificial Intelligence (technology)WhatsApp (product)Poipet scam network (threat_actor)