OpenAI Scam Network May Have Engaged Hundreds of Targets Across Multiple Fraud Schemes

The company said the operation may have interacted with hundreds of targets, with some conversations claiming individual victims lost thousands of dollars.

The investigation began after a lead from WhatsApp. OpenAI later shared threat signals with industry partners and relevant authorities, banned the linked ChatGPT accounts, and introduced measures intended to prevent the actors from returning to its services.

The case highlights how organized fraud groups can run several scams at once. Rather than relying on one criminal model, they can switch narratives, fake identities, and social-engineering tactics depending on what is most likely to convince a target.

OpenAI said the network likely originated in Cambodia and may have operated in or around Poipet, a city in Banteay Meanchey province that has repeatedly been linked in public reporting to online scam compounds and human-trafficking operations.

OpenAI Scam Network Unmasked

Operators used AI tools to build and maintain fake online personas, translate messages, draft promotional material, and help with everyday operational tasks.

Some users also used ChatGPT for administrative work, including internal announcements, staff communications, recruitment-related material, and records concerning working conditions.

The network carried out several fraud schemes simultaneously.

In one pattern, scammers used dating profiles to build a relationship with a victim before introducing a fraudulent investment opportunity involving cryptocurrency or spot gold trading.

Other operators maintained lengthy romantic exchanges under fictitious identities.

Some scammers posed as representatives of online gambling platforms. They promised bonuses, winnings, or rewards that did not exist.

Others impersonated law-enforcement agencies and told targets they had committed serious offences and needed to pay a fine immediately.

Despite the different stories, the activity followed a similar structure: create trust, generate urgency or emotion, and extract money. OpenAI describes this model as “the ping, the zing, and the sting.”

An AI-generated image created by a scammer in the network to promote a bogus investment scheme (Source: openai)
An AI-generated image created by a scammer in the network to promote a bogus investment scheme (Source: openai)

The “ping” involved outreach through messaging services such as WhatsApp and Telegram. Operators used translated or AI-generated conversations, dating-profile research, and social-media content to make fake identities seem credible.

The “zing” involved emotional manipulation. Messages promised guaranteed profits and “risk-free” investments, used romantic language, urged secrecy, and created urgency around fake bonuses or deadlines.

AI-generated images created by scammers in the network to advertise jobs in Cambodia on social media. Redactions added by OpenAI (Source: openai)
AI-generated images created by scammers in the network to advertise jobs in Cambodia on social media. Redactions added by OpenAI (Source: openai)

The “sting” was the financial request. Victims were instructed to make deposits, pay activation fees, settle false fines, or provide screenshots of bank transfers and account details as proof of payment.

The actors also created images of forged or misleading material, including passports, legal notices, stock-purchase confirmations, gambling interfaces, and promotional content for bogus investment schemes.

OpenAI also identified content suggesting possible links to human trafficking and forced criminality. Some users created social-media advertisements for “chatter” jobs in Poipet that offered flights, food, accommodation, visas, and work permits.

Other content appeared to concern the management of workers inside the operation. This included records of employee debts, salary deductions, disciplinary fines, loan repayments, recruitment incentives, immigration status, and visa overstays.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories