OpenAI: ChatGPT Aided Cambodia Scam Network

Help Net Security · Medium sophistication
Last updated August 3, 2026

OpenAI says it shut down a coordinated network of ChatGPT accounts linked to Cambodia that supported multiple real-world scams, including investment, romance, gambling, and law-enforcement impersonation. The group used AI to create fake personas, translate and generate persuasive messages on WhatsApp/Telegram, and pressure victims into sending money and sharing proof of payment. The operation appears tied to scam-compound activity and may have contacted hundreds of targets, with reported losses in the thousands of dollars per victim (unverified).

How the attack worked

OpenAI identified and banned a coordinated network of ChatGPT accounts likely tied to Cambodia's Preah Sihanouk province. The network used AI to build and manage fake online personas, translate messages, generate scam conversations, and produce promotional content for fraudulent schemes. The investigation reportedly began after a lead from WhatsApp, and the operation used both WhatsApp and Telegram to reach targets across investment, romance, gambling, and law enforcement impersonation scams.

The scams followed a structured pattern described as ping, zing, sting: outreach to make contact, emotional manipulation to build trust or urgency, and then extraction of money. Victims were pushed to send funds for fake rewards, activation fees, or fabricated fines, and were then asked to send screenshots of payments or share account information as proof.

Why it succeeded

Each scenario relied on a believable persona and a clear emotional hook. The investment pitch promised guaranteed returns and risk-free investments, while pressuring targets to act before a bonus expired. The romance scenario used romantic language and encouraged secrecy, isolating victims from outside input. The law enforcement impersonation scenario relied on the authority of a supposed official demanding an unexpected fine. In all cases, the combination of trust-building and urgency reduced the likelihood that a victim would pause and verify.

What to watch for

  • Guaranteed returns or risk-free investment language
  • Pressure to act quickly before an offer or bonus expires
  • Requests to keep a conversation or relationship secret
  • Demands to pay a fee, fine, or activation cost through chat apps
  • Requests for screenshots of payments or account details as proof

Building resistance

Organizations and individuals can reduce exposure by treating any guaranteed-return pitch as a red flag and verifying independently through official channels before engaging. Urgency, whether framed as a limited-time bonus or an unexpected fine, should trigger a pause rather than immediate action. No one should send money, payment screenshots, or account information to a contact known only through messaging apps. Requests to keep a conversation private are a common isolation tactic and should prompt a check with a trusted colleague or family member before continuing. Finance teams, HR and recruiting staff, and customer support teams handling inbound messages are particularly relevant audiences for this awareness, given the range of pretexts observed, from investment offers to law enforcement impersonation.

These lessons apply broadly since the pretexts span consumer-facing scenarios as well as workplace channels where employees might receive similar unsolicited contact through personal or shared messaging accounts.

Key findings

  • OpenAI banned a coordinated network of ChatGPT accounts likely originating from Cambodia’s Preah Sihanouk province.
  • The network used AI to create/manage fake online personas, translate messages, generate scam conversations, and produce promotional content for fraudulent schemes.
  • OpenAI’s investigation began after a lead from WhatsApp and the operation used platforms including WhatsApp and Telegram to reach targets.
  • Scams included investment, romance, gambling, and law enforcement impersonation, using a structured approach: “ping” (outreach), “zing” (emotion), “sting” (extract money).
  • Victims were pushed to send money for “fake rewards,” “activation fees,” or “fabricated fines,” then asked for screenshots of payments or account information as proof.
  • Some internal content suggested links to human trafficking/forced criminality associated with organized crime groups in East Asia.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance teams, Executives, HR/Recruiting teams (job-ad scam awareness), Customer support/trust & safety teams.
  • Affected industries: Consumers/General public, Financial services (investment-related fraud), Online dating/social platforms, Gambling/online gaming.
  • Attack channels: whatsapp, telegram.
  • Impersonated: A friendly investment contact using a fake persona, A romantic interest using a fake identity, Law enforcement (impersonation).

Red flags to watch for

  • Guaranteed returns / “risk-free” language
  • Pressure to act before an offer or bonus “expires”
  • Request to send payment proof screenshots
  • Push to move fast emotionally and keep the relationship/chat secret
  • Requests for money tied to vague “rewards” or urgent timelines
  • Asking for screenshots of transfers or account information
  • Authority figure demanding payment via chat app
  • Unexpected fine/penalty with urgency
  • Request for payment proof screenshots
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What scams did the Cambodia-linked network run using ChatGPT?

The network used ChatGPT to support investment, romance, gambling, and law enforcement impersonation scams, generating fake personas and persuasive messages sent over WhatsApp and Telegram.

How did the scammers pressure victims into paying?

They promised guaranteed returns and risk-free investments, then pressured victims to act before fake offers or bonuses supposedly expired, instructing them to send money to unlock rewards, pay activation fees, or settle fabricated fines.

What proof did scammers demand after a payment?

Victims were asked to provide screenshots of payments or share account information as proof, which helped the scammers verify compliance and continue the manipulation.

Why did the romance scam variant ask victims to keep chats private?

Scammers encouraged targets to keep conversations private to isolate them from friends or family who might raise concerns, making it easier to extract money without outside scrutiny.

Read the video transcript

There’s a scam network using ChatGPT to hit people on WhatsApp and Telegram with “risk‑free” investments and secret romances. OpenAI banned a coordinated group tied to Cambodia that used ChatGPT to spin up fake personas, translate chats, and run a playbook: ping you, zing your emotions, then sting you for cash. On WhatsApp, they push “guaranteed returns” and bonuses that “expire soon.” On Telegram, they build a secret romance, then ask you to send money and screenshots of your transfer or even account info. If anyone on WhatsApp or Telegram offers “risk‑free” returns or a secret relationship and then wants money or payment screenshots, stop, don’t send a thing, and report it to Security.

Similar attacks