Cyber Security News

OpenAI Reveals How Cybercriminals are Using ChatGPT to Run Scam Operation

Online scams are becoming more organized, more personal, and harder to spot. Criminal networks are now using artificial intelligence to create believable messages, fake identities, and fraudulent websites that help them reach victims at scale.

A recently disrupted operation used romance, investment, gambling, and law-enforcement impersonation scams to pressure people into sending money.

The campaign appears to have targeted victims through messaging and social platforms, including WhatsApp and Telegram.

Analysts from OpenAI identified a coordinated network that likely originated in Cambodia and may have operated around Poipet, a city repeatedly linked to scam compounds and trafficking concerns.

The company banned the accounts involved and shared relevant threat signals with industry partners and authorities.

OpenAI said in a report shared with Cyber Security News (CSN) that the operation shows how fraud groups can move between several scam types instead of relying on one script.

It also highlights the overlap between online fraud, organized crime, and the exploitation of people forced to work inside scam operations.

OpenAI Reveals How Cybercriminals are Using ChatGPT

The network used ChatGPT to support fake online personas, create promotional material, translate messages, and manage parts of its day-to-day work. The activity did not depend on one simple fraud method.

Operators created dating profiles, supposed investment experts, gambling representatives, and false law-enforcement identities.

They also used generated images to make forged passports, legal notices, stock-purchase confirmations, and gambling interfaces appear more convincing.

The group’s approach followed a familiar pattern: first make contact, then build emotion and trust, and finally demand money.

Readers can see how AI-generated text has also strengthened realistic phishing email attacks that rely on impersonation and carefully written social engineering.

A fake cryptocurrency trading interface created using ChatGPT by a scammer in the network (Source – OpenAI)

In investment and romance scams, criminals used friendly conversations to establish credibility before introducing cryptocurrency or spot-gold trading opportunities.

Victims were promised guaranteed returns or risk-free investments, claims that should always be treated as a warning sign.

Other victims were told they had won bonuses through online gambling platforms, only to be asked for deposits or activation fees.

Some were impersonated by supposed law-enforcement officials and pressured to pay invented fines for crimes they had not committed.

The scammers asked targets to provide screenshots of transfers or account details after payment.

This mirrors the wider pig butchering scam model, where criminals spend time building trust before pushing victims toward larger financial losses.

Fraud Networks and Forced Labor

The investigation also uncovered activity suggesting possible human trafficking and forced criminality. Some accounts created job advertisements for “chatter” roles in Poipet that offered flights, meals, accommodation, visas, and work permits.

OpenAI found internal material that appeared connected to employee debts, salary deductions, disciplinary fines, recruitment incentives, and immigration issues.

Other conversations referred to detention, escape attempts, and possible liability for people who may have been forced to work in the scam operation.

The company cautioned that it could not independently determine the circumstances of every individual involved.

Still, the findings align with reporting on Southeast Asia scam centers, where fraud, money laundering, and human trafficking can operate together.

The financial impact of this particular network remains unknown, although conversations reviewed by OpenAI suggested it may have contacted hundreds of targets.

AI-generated images created by scammers in the network to advertise jobs in Cambodia on social media (Source – OpenAI)

Individual victims were reportedly said to have lost thousands of dollars, but those claims could not be independently verified.

People should be cautious when an online stranger quickly raises investments, asks for secrecy, promises guaranteed returns, or creates urgency around a payment.

Victims should stop sending money, preserve messages and payment records, report the incident to the relevant platform, and contact local law enforcement.

The case also reinforces the need to verify unexpected claims independently. Whether a message appears to come from an investor, romantic partner, gambling platform, or official agency, users should avoid acting through links or contacts supplied by the sender.

Building Resilience Against Phishing & Malware and Analyze it in a safe environment – Power your SOC with ANY.RUN

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

2 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

12 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

13 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

13 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

13 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

13 hours ago