OpenAI has Ban Cambodia-Based Network Using ChatGPT to Power Multi-Vector Cyber Scams
OpenAI announced it disrupted a Cambodia-based criminal operation that misused its ChatGPT AI chatbot to run widespread investment, romance, gambling, and law enforcement impersonation scams. In response, the company banned a coordinated network of ChatGPT accounts operating out of Poipet, Southeast Asia a region long associated with cyber-scam compounds and human trafficking.
The network leveraged OpenAI’s models to build and maintain fake online personas, draft and translate messages to targets, create promotional material for fraudulent schemes, and handle daily administrative tasks.
To attract recruits, the operation generated social media ads targeting users in Bangladesh and India for “chatter” jobs in Poipet. The postings promised an $800 base salary with a $100 full-attendance bonus, along with flight tickets, free meals and housing, work permits, and one-year Cambodian visas.
Additionally, a subset of accounts used the AI tool for internal administration drafting announcements, translating staff communications, and tracking personnel records such as employee debts, fines, loan repayments, work permits, and visa statuses. OpenAI confirmed it investigated and disrupted the operation in partnership with Meta-owned WhatsApp.
“The operation illustrates an important reality about modern scam networks; organized criminal groups rarely restrict themselves to a single type of scam,” OpenAI noted. “Instead, they opportunistically employ whatever narratives, personas, and tactics they think will be most effective to deceive victims.”
The threat actors ran multiple scam operations in parallel, blending tactics to maximize their success. Beyond using fake dating profiles to lure victims into fraudulent crypto and gold investments, the group engaged in prolonged romantic conversations using synthetic personas or posed as representatives of online gambling platforms promising fake bonuses and payouts.
Other accounts within the network impersonated law enforcement, using manufactured urgency to demand immediate fine payments for fabricated criminal offenses. To execute these schemes, the operators created fake dating profiles, fake investment advisors, and bogus authority figures, while using AI to generate forged passports, legal notices, stock purchase receipts, and fake gambling platform interfaces.
See also: Samsung Targets AI Memory Dominance with Next-Gen 3D zHBM and 400-Layer NAND
According to OpenAI, the attack chain follows a three-step method dubbed “ping-zing-sting.” Scammers first initiate contact on messaging apps like WhatsApp and Telegram (“ping”), build trust through ongoing conversation (“zing”) and finally trick victims into depositing funds, paying activation fees, or settling bogus fines (“sting”) backed by fabricated receipts.
Notably, several accounts produced content linked to human trafficking and forced labor operations common among East Asian crime syndicates. These networks frequently lure job seekers with high-paying offers, only to seize their passports and trap them in slave-like conditions.
“While the full financial impact remains unknown, the scammers’ own communications suggest the network interacted with hundreds of targets across various fraud schemes, with some victims losing thousands of dollars,” OpenAI stated, noting it could not independently verify those amounts.
The incident highlights how cybercriminals are adopting AI to dramatically scale and speed up their operations even as frontier models face growing scrutiny for attempting to exploit real-world systems during automated cybersecurity evaluations.





