
Fake Zoom/Teams Calls Used to Steal Crypto Wallets
North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…
OpenAI says it shut down a coordinated network of ChatGPT accounts linked to Cambodia that supported multiple real-world scams, including investment, romance, gambling, and law-enforcement impersonation. The group used AI to create fake personas, translate and generate persuasive messages on WhatsApp/Telegram, and pressure victims into sending money and sharing proof of payment. The operation appears tied to scam-compound activity and may have contacted hundreds of targets, with reported losses in the thousands of dollars per victim (unverified).
OpenAI identified and banned a coordinated network of ChatGPT accounts likely tied to Cambodia's Preah Sihanouk province. The network used AI to build and manage fake online personas, translate messages, generate scam conversations, and produce promotional content for fraudulent schemes. The investigation reportedly began after a lead from WhatsApp, and the operation used both WhatsApp and Telegram to reach targets across investment, romance, gambling, and law enforcement impersonation scams.
The scams followed a structured pattern described as ping, zing, sting: outreach to make contact, emotional manipulation to build trust or urgency, and then extraction of money. Victims were pushed to send funds for fake rewards, activation fees, or fabricated fines, and were then asked to send screenshots of payments or share account information as proof.
Each scenario relied on a believable persona and a clear emotional hook. The investment pitch promised guaranteed returns and risk-free investments, while pressuring targets to act before a bonus expired. The romance scenario used romantic language and encouraged secrecy, isolating victims from outside input. The law enforcement impersonation scenario relied on the authority of a supposed official demanding an unexpected fine. In all cases, the combination of trust-building and urgency reduced the likelihood that a victim would pause and verify.
Organizations and individuals can reduce exposure by treating any guaranteed-return pitch as a red flag and verifying independently through official channels before engaging. Urgency, whether framed as a limited-time bonus or an unexpected fine, should trigger a pause rather than immediate action. No one should send money, payment screenshots, or account information to a contact known only through messaging apps. Requests to keep a conversation private are a common isolation tactic and should prompt a check with a trusted colleague or family member before continuing. Finance teams, HR and recruiting staff, and customer support teams handling inbound messages are particularly relevant audiences for this awareness, given the range of pretexts observed, from investment offers to law enforcement impersonation.
These lessons apply broadly since the pretexts span consumer-facing scenarios as well as workplace channels where employees might receive similar unsolicited contact through personal or shared messaging accounts.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
The network used ChatGPT to support investment, romance, gambling, and law enforcement impersonation scams, generating fake personas and persuasive messages sent over WhatsApp and Telegram.
They promised guaranteed returns and risk-free investments, then pressured victims to act before fake offers or bonuses supposedly expired, instructing them to send money to unlock rewards, pay activation fees, or settle fabricated fines.
Victims were asked to provide screenshots of payments or share account information as proof, which helped the scammers verify compliance and continue the manipulation.
Scammers encouraged targets to keep conversations private to isolate them from friends or family who might raise concerns, making it easier to extract money without outside scrutiny.
There’s a scam network using ChatGPT to hit people on WhatsApp and Telegram with “risk‑free” investments and secret romances. OpenAI banned a coordinated group tied to Cambodia that used ChatGPT to spin up fake personas, translate chats, and run a playbook: ping you, zing your emotions, then sting you for cash. On WhatsApp, they push “guaranteed returns” and bonuses that “expire soon.” On Telegram, they build a secret romance, then ask you to send money and screenshots of your transfer or even account info. If anyone on WhatsApp or Telegram offers “risk‑free” returns or a secret relationship and then wants money or payment screenshots, stop, don’t send a thing, and report it to Security.

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Russian authorities allege Telegram was used to recruit and pressure young people into real-world attacks, with “Ukrainian agents” posing as young women via a…

Researchers documented a real phishing operation that used Telegram “secret chats” to send fake security warnings to specific people, including an exiled…

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

Scammers are posing as FBI staff who supposedly handle IC3 (Internet Crime Complaint Center) reports to trick people who have already been scammed once. The…