HackMyIP
← Back to News
2026-08-05 The Hacker News

OpenAI Disrupts ChatGPT-Powered Poipet Scam Network

AI ThreatsPhishingDeepfake

OpenAI announced the disruption of a Cambodia-based scam operation headquartered in Poipet, banning a coordinated cluster of ChatGPT accounts used to run investment fraud, romance scams, gambling schemes, and law enforcement impersonation across multiple platforms. The accounts, likely originating from Southeast Asia, leveraged OpenAI's generative AI to craft fake online personas, translate messages to scam targets, generate promotional content, and handle administrative tasks within the criminal organization. According to OpenAI, the investigation was conducted in partnership with Meta-owned WhatsApp, underscoring the cross-platform nature of the operation.

The network exploited ChatGPT to produce social media advertisements recruiting so-called "chatter" workers from Bangladesh and India, offering an $800 base salary plus $100 attendance bonuses, flights, accommodation, meals, and one-year Cambodia visas. Internal administrative use of the AI included drafting announcements, translating staff communications, and documenting employee debts, salary deductions, fines, and immigration status. Operatives also used the tool to generate synthetic identities, forge passport images and legal notices, fabricate stock-purchase confirmations, and clone gambling platform interfaces, making it difficult for victims to distinguish fraud from legitimate activity.

The attack chain followed a three-phase approach dubbed "ping-zing-sting": initial contact to build trust, grooming through romantic or financial narratives, and final extraction. Threat actors blended cryptocurrency and spot gold investment scams with romance lures, posed as online gambling representatives offering fake bonuses, and impersonated law enforcement to pressure targets into paying fabricated criminal fines. "Organized criminal groups rarely restrict themselves to a single type of scam," OpenAI noted, emphasizing that modern fraud networks opportunistically combine personas, narratives, and tactics to maximize success. Given the rise of AI-generated content used in social engineering, users should regularly verify whether their personal information has been exposed using an email breach checker, test their connection for leaks with a DNS leak test, and audit their browser exposure via a browser fingerprint test to reduce the risk of identity-driven targeting.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →