OpenAI Disrupts Cambodia-Based Scam Network That Used ChatGPT
OpenAI banned a Cambodia-based ChatGPT scam network running investment, romance, gambling and police-impersonation fraud, with signs of human trafficking near Poipet.

Updated
Why it matters
- OpenAI banned a coordinated ChatGPT account network very likely operating in or around Poipet, Cambodia, after a lead from WhatsApp.
- The network ran investment, romance, gambling and law-enforcement-impersonation scams simultaneously, following a 'ping, zing, sting' pattern.
- User activity included trafficking indicators: job ads for 'chatter' roles, debt records, and conversations referencing detention and escape attempts; the operation may have targeted hundreds of victims losing thousands of dollars each.
OpenAI has banned a coordinated network of ChatGPT accounts that it assesses very likely originated in Cambodia and operated in or around Poipet, a city in Banteay Meanchey province that public reporting has repeatedly linked to online scam compounds and trafficking operations. The company opened its investigation after a lead from WhatsApp and has since shared additional threat signals with industry partners and relevant authorities.
The disruption, disclosed earlier this year, offers one of the clearest public pictures to date of how criminal groups are folding commercial AI tools into industrial-scale fraud. The stakes are considerable: Southeast Asian scam compounds have displaced billions of dollars from victims worldwide, and this case shows AI models now assist at nearly every stage of the fraud pipeline, from writing the first message to forging the documents that close the con.
A multi-scam operation, not a single fraud
OpenAI's report stresses a structural point about modern scam networks: organized criminal groups rarely restrict themselves to a single type of scam. "Instead, they opportunistically employ whatever narratives, personas, and tactics they think will be most effective to deceive victims," the company wrote. In its investigations, OpenAI routinely observes actors moving between scam types, or combining multiple scam techniques within a single operation.
This network ran four distinct schemes simultaneously: investment fraud, romance scams, gambling platform cons, and impersonation of law enforcement agencies. Operators frequently blended them. In one recurring pattern, scammers used dating personas to build trust before introducing fraudulent investment opportunities involving cryptocurrencies and spot gold trading. Other users carried on lengthy romantic conversations under fictitious identities, posed as representatives of online gambling platforms offering fake bonuses, or impersonated law enforcement to tell targets they needed to pay fines for serious criminal offenses.
The network used ChatGPT to create and operate fake online personas, generate and translate messages sent to targets, produce promotional content for fraudulent schemes, and assist with day-to-day operations. As with past scam networks OpenAI has disrupted, a subset of users also employed the tool for administrative work — drafting internal announcements, translating messages between staff, and documenting matters that appeared related to recruitment, immigration status, working conditions, and employee discipline.
The ping, the zing, the sting
Despite the variety of narratives, OpenAI found one consistent underlying pattern of deceptive behavior across the network, which it describes in three stages: the ping, the zing, and the sting.
The ping is the outreach. The network used ChatGPT to translate and generate conversations with targets on messaging platforms such as WhatsApp and Telegram. Scammers also created social media content and researched dating profile material to support their fake personas.
The zing generates emotion. Scammer messages frequently relied on emotional pressure and trust-building techniques, including promises of guaranteed returns and "risk-free" investments, romantic language, instructions to keep conversations secret, and urgent requests for action before fictional bonuses expired.
The sting extracts the money. Scammers instructed victims to make deposits to unlock purported rewards, pay activation fees, settle fictitious fines, and then provide screenshots of transfers or account information as proof of payment.
The network also used the model to generate images of forged documents, including passports, legal notices, stock-purchase confirmations, and gambling platform interfaces. OpenAI's report includes examples: a fake cryptocurrency trading interface, an AI-generated image promoting a bogus investment scheme, and AI-generated job advertisements posted to social media.
Human trafficking indicators
The most disturbing findings sit outside the scam scripts themselves. Some users in the network generated content suggesting links to human trafficking and forced criminality.
This included social-media advertisements for "chatter" jobs in Poipet that promised flights, accommodation, meals, visas, and work permits — inducements consistent with extensive public reporting, including from The Wall Street Journal and Amnesty International, describing organized crime groups in Southeast Asia that recruit workers with promises of legitimate employment before trapping them in systems of debt bondage and coercion.
Users also maintained records of employee debts, salary deductions, disciplinary fines, and loan repayments, and translated discussions about immigration status, work permits, visa overstays, and recruitment incentives. Some conversations referenced apparent detention, escape attempts, and potential criminal liability for people who had been trafficked and forced to work in scam operations.
OpenAI is careful about what it can and cannot conclude. "While we cannot independently determine the circumstances of every individual involved, the activity serves as a reminder that the people conducting scams can themselves be victims of exploitation," the company wrote. Reuters reported in February that Thai and Cambodian police freed 215 foreigners in a raid on a scam center, underscoring the scale of the problem in the region.
Impact and scale
OpenAI banned the ChatGPT accounts associated with the operation, shared relevant indicators with industry partners and authorities, and took steps to make it harder for the actors to regain access to its products and services.
The full financial losses remain unknown. Based on the scammers' own communications, OpenAI estimates the operation may have interacted with hundreds of targets across multiple scam types. User conversations referenced individual victims losing thousands of dollars, though OpenAI says it cannot independently verify those claims.
Why it matters
OpenAI draws two conclusions from the case, and both carry weight for policymakers, platforms, and researchers tracking AI misuse.
First, organized scam networks can be highly diversified, operating multiple fraud schemes simultaneously rather than narrowly adhering to a single scam type. That diversification complicates detection and takedown efforts, because a disruption aimed at one fraud narrative leaves the rest of the operation intact.
Second, the boundaries between online fraud, organized crime, and human trafficking are often blurred. "Effective disruption therefore requires targeting not just the victim-facing scam activity, but also the criminal organizations that orchestrate and profit from it," OpenAI wrote.
The case also illustrates the dual role AI vendors now play. The same model capabilities that help small businesses translate content and draft documents also lowered the cost of running multilingual, multi-scheme fraud at scale. OpenAI's threat intelligence reports from June and October 2025 document similar patterns in prior disruptions, suggesting this Cambodian operation is part of a persistent and evolving trend rather than an isolated incident.
The company's disclosure practice itself — publishing tactics, indicators, and stage-by-stage attack patterns — is becoming a key input for the broader ecosystem of platforms and law enforcement agencies that must intercept these operations before the sting lands.
Original: wsj.com
More from Sophie Lindqvist
Show full bio
Staff writer covering marketplaces and e-commerce at AI In Context.
115 articles
Related articles
- OpenAI Bans ChatGPT Accounts Behind Fake FBI Recovery Scam
- OpenAI Maps the Anatomy of AI-Enabled Romance Scams
- OpenAI Bans Cambodia-Based Accounts Running AI Dating Scams
- How an OpenAI Investigator's Own Phone Helped Bust an AI Task Scam
- OpenAI Bans Accounts Linked to DPRK Threat Actors Using AI for Intrusion Research