"The operation illustrates an important reality about modern scam networks: organized criminal groups rarely restrict themselves to a single type of scam," OpenAI said.
OpenAI announced it had disrupted a coordinated cluster of ChatGPT accounts that the company says were being used to run a multi-pronged scam operation based in Poipet, Cambodia. Working in partnership with Meta-owned WhatsApp, the company said it banned accounts it believes originated in Southeast Asia and used the generative AI to create, manage, and scale a range of fraudulent schemes — from romance and investment fraud to gambling cons and law‑enforcement impersonation.
OpenAI and WhatsApp: coordinated disruption
OpenAI described the action as the result of an investigation carried out with WhatsApp. The company said the banned cluster of ChatGPT accounts was likely operating from the city of Poipet — a location the report links to previous scam compounds and trafficking concerns — and that the accounts were directly supporting the scammers' day‑to‑day operations. OpenAI framed the disruption as an example of criminal groups “opportunistically” using whatever narratives and tactics will deceive victims most effectively.
Poipet account cluster: tools, roles, and recruitment ads
The cluster reportedly used OpenAI's models to craft fake online personas, generate and translate messages sent to targets, and produce promotional content. Among the promotional content were social‑media advertisements for “chatter” jobs in Poipet that specifically targeted users in Bangladesh and India. Those ads promised a base salary of $800, a $100 “full attendance” bonus, flight tickets, free accommodation, meals, a 1‑year Cambodia visa, and work permits — inducements the company says were part of the recruitment narrative.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildHow the network ran scams: ping‑zing‑sting
OpenAI described the operation's attack chain as a three‑step approach it calls ping‑zing‑sting. Scammers began with outreach on messaging platforms such as WhatsApp and Telegram, engaged in trust‑building conversations, and then asked targets to make deposits, pay activation fees, or settle alleged fines. After payment, victims were shown fabricated proof — fake screenshots of transfers or account balances — as part of the deception.
The actors ran multiple schemes in parallel and blended tactics. They used dating personas to establish trust and then steered victims into fraudulent investment opportunities involving cryptocurrencies and spot gold trading; posed as representatives of gambling platforms offering fake bonuses and winnings; and impersonated law enforcement to create a false sense of urgency and demand payments for supposed legal violations. To support those efforts the accounts produced images of forged documents, including passports, legal notices, stock‑purchase confirmations, and gambling platform interfaces, and created fake dating profiles, fictitious investment experts, and fraudulent law‑enforcement personas.
Administrative automation and human‑trafficking indicators
Beyond direct victim contact, a subset of accounts reportedly used the AI tool for internal administration: drafting internal announcements, translating messages between staff, and documenting employee debts, salary deductions, fines, loan repayments, visa overstays, work permits, immigration status, and recruitment incentives. OpenAI said some generated content was consistent with human trafficking and forced labor tied to organized crime in East Asia — including recruiting people with false promises of lucrative jobs, confiscating passports, and forcing them to work in “slave‑like conditions.”
The company noted the network “may have interacted with hundreds of targets across multiple scam types,” and that user conversations referenced individual victims losing thousands of dollars, though OpenAI said it could not independently verify those loss figures.
What this means for technologists, policymakers, and the public
- Technologists and security teams: The case shows how AI can be repurposed as an operational multiplier, both for external engagement (message generation, persona creation) and internal administration (recording debts, translating staff communications). Defenders will need detection approaches that account for AI‑generated content used across platforms.
- Policymakers and platform operators: OpenAI's cooperation with WhatsApp highlights cross‑platform and cross‑company coordination as a tool for disruption. The cluster’s transnational footprint — operating from Poipet and targeting users in Bangladesh and India — underscores the cross‑border character of such networks and the need for collaborative responses.
- End users and the public: Job advertisements promising $800 plus flights, visas, and work permits, requests to pay activation fees or fines, and unsolicited romantic or investment contacts should be treated cautiously. The operation illustrates how scammers combine believable narratives and fabricated documentation (fake passports, legal notices, screenshots) to manufacture trust.
OpenAI framed the incident as evidence that threat actors are rapidly developing AI‑augmented offensive capabilities that increase the speed and scale of campaigns. It also warned that frontier models have been observed in CTF‑style cyber evaluations targeting real systems and individuals — a point the company used to illustrate the rising complexity of AI‑assisted threats.
The disruption removes one cluster of accounts from active use, but OpenAI's account shows how a single model can be applied across recruitment, administration, persuasion, and forgery. The company's own caveat — that reported financial losses remain unverified and that the network “may have interacted with hundreds of targets” — leaves the human and economic toll only partially measured. What the record does make clear is that organized criminal groups are using AI to make old scams faster, broader, and harder to spot.
https://thehackernews.com/2026/08/openai-disrupts-poipet-scam-network.html




