OpenAI disrupts Cambodia-based AI scam network using ChatGPT

Sudhanshu Ranjan
Written by Sudhanshu Ranjan

OpenAI has disrupted a Cambodia-based scam network that allegedly used ChatGPT to support investment fraud, romance scams, gambling schemes, and law enforcement impersonation campaigns.

According to OpenAI, the Poipet-based business employed AI to produce promotional content, interpret scam messages, establish fictitious personalities, and help with internal operations. The investigation, which was carried out in conjunction with WhatsApp, emphasises how AI is increasingly being used in cybercrime and how tech companies are still working to identify and stop criminal networks.

Scam crackdown

The investigators discovered a group of ChatGPT accounts operating out of Poipet, which has a reputation for operating human trafficking and scam facilities. Investment scams, cryptocurrency scams, romance scams, fake gambling, and police impersonations were all being carried out concurrently by these accounts.

The results demonstrated that thieves were employing AI for more than just drafting messages. They incorporated ChatGPT into all aspects of daily operations, including internal communication, document preparation, customer interaction, translations, and recruitment. AI was essentially incorporated into their workflow and used as a productivity tool. To restrict the operation’s scope, OpenAI shared intelligence with partners and banned the accounts.

How scam network used ChatGPT

Personalised content, immediately convincing dating profiles, phony investment advisers, customer service avatars, and even fictitious government officials were all produced using generative AI. Additionally, criminals used AI-generated translations to communicate between nations, eliminating language barriers without the necessity for bilingual employees.

Fake recruiting aimed at job seekers in Bangladesh and India was the unsettling aspect. Salaries of about $800 a month, bonuses, flights, lodging, work permits, and Cambodian visas were all promised in advertisements.

Victims were then trafficked into scam compounds, where passports were taken, and they were forced into online fraud. AI was also used to generate forged passports, legal notices, gambling interfaces, and financial documents, all designed to make scams look legitimate.

The “Ping-Zing-Sting” scam strategy

The victims were identified by the cybercriminals using a three-tiered method. Using apps like WhatsApp or Telegram, the initial contact was made during the “ping” phase with either friend requests or incentives for investments or wagers. Relationships were formed during the “zing” period; investment scammers would discuss their achievements, while romance scammers would converse for weeks.

Finally, the “sting” stage demanded deposits, activation fees, crypto investments, or fake fines. Victims were shown manipulated screenshots and transaction confirmations to make the scams look real.

Links between the fraudulent channels and human trafficking in Southeast Asia were also found. Fake job advertisements would be used to attract workers, who would then be forced to participate in cybercrimes under appalling conditions.

If they failed to achieve their fraud objectives, they would be subject to threats and harassment, have their passports seized, and have their movements restricted. AI would prepare announcements and translate messages to help managers within the company.

AI’s growing role in cybercrime

Cybercriminals now have a lower barrier thanks to generative AI. It is now possible to complete tasks that formerly required expert writers, translators, or designers in real time. AI is used by criminal organisations for large-scale social engineering, multilingual communication, tailored fraud, and quicker content generation. This enables them to continue plausible interactions while simultaneously targeting thousands of victims.

AI was employed by the scam network to make operations more scalable and believable across a variety of fraud types. Investment fraud involves the creation of fictitious financial documents and advisers in order to steal deposits.

AI-generated conversations were used to enable the romance scams before the con artists could demand payment. Promotional texts and fictitious victories were used in the gambling scams to trick victims into making deposits.

Finally, recruitment frauds enticed victims, often into trafficking operations, by using job advertisements and translations. When combined, these strategies demonstrate how generative AI is being incorporated into every phase of contemporary cybercrime.

OpenAI’s response

The coordinated criminal activity across many platforms was discovered thanks in large part to intelligence sharing, underscoring the necessity of cross-platform collaboration. To prevent the operation from spreading, OpenAI suspended the previous accounts and shared intelligence with its partners.

Additionally, OpenAI revealed several crucial warning signs, such as demands for cryptocurrency transactions or activation charges, assurances of guaranteed returns, fast-tracked online relationships, official alerts regarding the need to make payments instantly via messaging apps, and overseas employment opportunities with highly exaggerated salaries or even free travel. The best countermeasure is to remain suspicious and confirm identities officially.