OpenAI Maps the Anatomy of AI-Enabled Romance Scams
OpenAI's February 2026 case study breaks AI-enabled romance scams into ping, zing, and sting stages, with ChatGPT used to craft convincing cold-contact messages.

Updated
Why it matters
- OpenAI's February 2026 case study describes a three-stage scam pattern: the ping (cold contact), the zing (generate emotion), and the sting (extract money).
- Threat actors used ChatGPT to generate messages that were 'more engaging and less obviously non-native than traditional scams,' including a Cambodia-based romance operation first exposed in 2025.
- OpenAI assesses that a scam's distribution method — scattershot or targeted — plays a significant role in its success, regardless of how much the operation used AI.
OpenAI has dismantled a recurring three-stage playbook that criminal networks now run with the help of ChatGPT: the ping, the zing, and the sting. The company laid out the framework in a case study originally published in its February 2026 report on disrupting malicious uses of AI, and the details matter for anyone tracking how generative models change the economics of fraud.
OpenAI began publicly reporting on scam-network disruptions a year ago, in its February 2025 update on malicious uses of its models. Since then, the company says it has taken down scam operations from multiple regions of the world. They included "task" scams, which convince victims to pay money in order to access non-existent earnings from trivial tasks, and investment scams, which push targets to put money into non-existent investment companies.
The romance scam predates AI by decades. A scammer poses as a potential romantic partner, convinces the target they have found a love match, and then asks for ever-larger sums of money. OpenAI's first published scam disruption featured a newly established criminal operation in Cambodia that had used ChatGPT to generate messages for a romance scam, some of which were spread on social media. The company has disrupted various attempted romance scams since.
The ping, the zing, the sting
As OpenAI wrote in June 2025, these and other scams tend to follow a common pattern in their use of AI — a pattern the company describes as "the ping (cold contact), the zing (generate emotion), and the sting (extract money)."
The ping is the cold contact. The scammer generates content designed to catch a potential target's attention by appealing to their interests. The "pig butchering" scam OpenAI reported in 2025 frequently targeted American men in their 40s working in medical professions by replying to their social media posts about golf. Other operations used cold-call SMS messages or fake recruitment messages; the most recent romance scam case OpenAI describes used social media ads. In each case, the threat actors used ChatGPT to generate messages that, in OpenAI's words, "might be more engaging and less obviously non-native than traditional scams."
That last point is the core AI contribution. Language models remove the broken grammar and awkward phrasing that once made scam messages easy to flag. The result is a first contact that reads like it came from a peer.
The zing is the emotional hook. The scammer generates content designed to trigger strong emotions and make the target easier to manipulate. Romance scams aim for attraction. Other variants stoke excitement about a lucrative deal, fear of missing an opportunity, or alarm about an alleged legal risk or unpaid bill. Sometimes the zing rides in the same message as the ping — for example, the cold-call SMS messages from the operation OpenAI exposed in June 2025 under the name "Wrong Number," which included details of implausibly high returns for little work.
The sting is the extraction. The scammer generates content designed to convince the target to hand over money, and the stated reasons vary enormously. Romance scams may ask the target to invest in the beloved's business or cover a fabricated financial crisis. "Task" scams tell targets to pay money in so they can access fictional earnings. Investment scams direct money into non-existent vehicles.
Distribution is the backbone
As the framework makes clear, an essential component of any scam is the distribution network. The operations OpenAI has exposed sent their pings via SMS, encrypted messaging apps, social media posts, online ads, or a combination of all of them. Pre-AI scams relied on emails, phone calls, and — in the nineteenth century — letters and telegrams. The channel changes. The con does not.
Distribution strategy varies. Many scams take a scattergun approach, but some attempt precision targeting. The "pig butchering" operation reported in February 2025 focused on topics such as golf. Another romance scam used social media ads to target young men in Indonesia. Celebrity scams typically pose as a famous person and then target that person's fan groups.
OpenAI cautions that the fragmentary nature of the evidence makes it hard to reliably compare the scams it disrupted. But the company's assessment is blunt on one point: "the scam's chosen distribution method (e.g., scattershot or targeted) plays a significant role in each scam's ability to successfully reach and exploit its targets, regardless of the degree to which the operation used AI for different functions."
In other words, the model-generated message matters, but reach and targeting decide how much damage the operation can do. For platforms, banks, and regulators weighing where to intervene, that places distribution infrastructure — social ads, SMS gateways, encrypted-messaging funnels — at the center of the fight against AI-assisted fraud, alongside the model providers themselves.
Original: cdn.openai.com
More from Rebecca Stone
Show full bio
Correspondent covering consumer brands and retail at AI In Context.
135 articles
Related articles
- OpenAI Disrupts Cambodia-Based Scam Network That Used ChatGPT
- How an OpenAI Investigator's Own Phone Helped Bust an AI Task Scam
- OpenAI Bans ChatGPT Accounts Behind Fake FBI Recovery Scam
- OpenAI Bans Cambodia-Based Accounts Running AI Dating Scams
- OpenAI Bans Accounts Reviving Russia's 'Stop News' Influence Operation