Poipet Scam Ring Used ChatGPT for Romance & Fines

The Hacker News · High sophistication
Last updated August 5, 2026

OpenAI says it disrupted a Cambodia-based scam network operating from Poipet that used ChatGPT to scale romance, investment, gambling, and law-enforcement impersonation scams. The group used messaging apps to build trust, then pressured victims to pay deposits, activation fees, or fake fines, backing the story with forged documents and screenshots.

Key findings

  • OpenAI says it banned a coordinated network of accounts likely operating from Poipet, Cambodia, tied to multi-scam activity.
  • The group used ChatGPT to create fake personas, write/translate scam messages, and generate promotional materials.
  • Scams included romance/investment (“crypto” and “spot gold trading”), gambling-bonus scams, and law-enforcement impersonation demanding payments.
  • OpenAI described a repeatable workflow: outreach on WhatsApp/Telegram, trust-building, then demands for deposits/fees/fines supported by fake screenshots and forged documents.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, HR/Recruiting, Customer support.
  • Affected industries: Consumers/individuals, Financial services (crypto/investment), Online dating, Online gambling, Social media and messaging platforms.
  • Attack channels: whatsapp, telegram.
  • Impersonated: Dating match using a synthetic identity (fake persona), Representative of an online gambling platform, Law enforcement agency.

Awareness takeaways

  • Treat unexpected messages on WhatsApp/Telegram that build trust and then ask for money as high-risk, stop and verify via a trusted, offline method.
  • Be skeptical of “proof” shown only as screenshots (payments, accounts, legal notices); screenshots are easy to fake.
  • Watch for impersonation + urgency (especially law enforcement or compliance threats); real authorities don’t demand immediate fines via chat apps.
  • Assume scammers can rapidly tailor and translate messages using AI, making messages look more polished and personal than older scams.

Red flags to watch for

  • New online relationship quickly pivots to money/investments
  • Pressure to deposit funds or pay fees to participate
  • “Proof” provided only via screenshots or unverifiable account pages
  • Unexpected message claiming winnings/bonuses
  • Payment required to receive money
  • Requests to continue only inside messaging apps
  • Authority impersonation combined with urgency and threats
  • Demand for payment to resolve legal issues via chat
  • Legal “proof” provided as images/screenshots instead of verifiable case details
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: a perfect match from a dating app messages, “Hey, your profile stood out. Want to chat here on WhatsApp?” OpenAI just shut down a Poipet, Cambodia scam ring using ChatGPT to run romance, crypto and spot-gold “tips,” fake gambling bonuses, even law-enforcement fines over WhatsApp and Telegram. Their playbook is “ping–zing–sting”: first ping you on WhatsApp or Telegram, then zing you with long, friendly chat, and finally sting you with deposits, activation fees, or fake fines backed only by screenshots and forged documents. If any chat relationship suddenly pivots to deposits, activation fees, or fines, especially with screenshot “proof”–your move is simple: stop, don’t pay, and call the real person or organization using a number you already trust.

Similar attacks

OpenAI: ChatGPT Aided Cambodia Scam Network

OpenAI: ChatGPT Aided Cambodia Scam Network

OpenAI says it shut down a coordinated network of ChatGPT accounts linked to Cambodia that supported multiple real-world scams, including investment, romance, gambling, and law-enforcement impersonation. The group used AI to create fake personas, translate and generate persuasive messages on…

August 3, 2026
Handala Uses Fake “Support” Chats to Drop Malware

Handala Uses Fake “Support” Chats to Drop Malware

Researchers linked the Iran-aligned Handala Hack persona to a Telegram-controlled backdoor (HEAVYGRAM) that can steal passwords and exfiltrate chat data. The campaign reportedly starts with social engineering on messaging apps (Telegram, WhatsApp, Instagram), where the attacker pretends to offer…

September 18, 2026
Iranian “Chosen Brick” Lures Sent via Telegram

Iranian “Chosen Brick” Lures Sent via Telegram

UK, US, and Dutch agencies warned that Iranian state-linked actors used social messaging apps to build trust with dissidents, journalists, and activists before sending disguised files that install Windows malware. The attackers often impersonated someone the target already knows or “technical…

September 17, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026
Passkey Helpdesk Scam Hijacks Microsoft Accounts

Passkey Helpdesk Scam Hijacks Microsoft Accounts

Microsoft described two real-world campaigns: an invoice fraud blast impersonating executives to trick finance teams into ACH payments, and a passkey-themed helpdesk scam that steals or bypasses authentication to take over Microsoft cloud accounts. In the second campaign, victims are called or…

September 13, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026