OpenAI Disrupts Cambodia ChatGPT Scam Ring Targeting Indian Victims
OpenAI announced it has disrupted a network of cyber scam centers in Cambodia that weaponized ChatGPT to conduct investment fraud, romance scams, and human trafficking operations targeting Indian nationals. The activity was traced to Poipet, a city with established ties to Chinese-organized scam operations, where operators integrated the large language model into nearly every stage of their fraud pipeline. According to OpenAI's investigation, scammers used ChatGPT to generate fake online personas, translate outreach messages to targets in multiple languages, and produce promotional content for fraudulent schemes — a workflow that illustrates how AI threats are now scaling traditional cybercrime operations. WhatsApp first alerted OpenAI to the activity, and the company subsequently banned the associated accounts, though it could not quantify total financial losses.
The network leveraged ChatGPT to fabricate convincing supporting documents, including AI-generated images of passports, legal notices, stock purchase confirmations, and mock gambling platform pages. Operators also used the model to assist with day-to-day business tasks such as drafting internal announcements, translating staff communications, and creating recruitment materials. These tactics blend classic phishing techniques with generative AI output, making fraudulent offers harder to distinguish from legitimate communications. Targets concerned about exposure to similar schemes can verify compromised credentials using a breach checker and audit their exposure with a privacy checkup.
Recruitment fliers promising free flights, accommodation, and work visas were distributed primarily in India, drawing workers into trafficking operations where the network maintained records of employee debts, salary deductions, disciplinary fines, and loan repayments. OpenAI noted that some internal conversations referenced detention, escape attempts, and criminal liability for trafficked workers forced to operate the scam infrastructure. Victims and operators alike often reuse passwords across services, a weakness that can be tested with a password checker to identify credentials exposed in known leaks.
The Cambodia case emerges alongside a broader escalation in AI-enabled fraud. INTERPOL published a separate study this week finding that more than half of all cybercrime across Africa now involves artificial intelligence, with law enforcement in 36 surveyed member states reporting that AI automates every stage of the attack lifecycle — from reconnaissance and phishing to extortion and evasion. In one Uganda incident, AI-generated audio and video impersonating a public figure drove losses exceeding $2 million in a fraudulent investment scheme. Experts warn that Southeast Asian scam centers are expanding into South Asia and Africa, signaling that AI-powered fraud operations are becoming a persistent global threat rather than a regional phenomenon.