OpenAI shut down a coordinated ChatGPT account network operated from Cambodia that ran investment fraud, romance scams, gambling impersonation, and law-enforcement extortion against hundreds of victims. A WhatsApp tip triggered the investigation. OpenAI published findings on July 31, 2026. Victim conversations showed losses in the thousands of dollars.

The network deployed ChatGPT across four operational layers: persona construction (fake dating profiles, fictitious advisors, forged law-enforcement IDs), message generation and translation between Chinese supervisors and local workers, promotional content seeding fake schemes, and internal HR administration tracking debt, salary deductions, fines, and visa status. Records documented debt bondage mechanics and detention conditions at the Poipet compound in Banteay Meanchey province.

OpenAI's analysis names the pattern ping-zing-sting. Ping: ChatGPT generates and translates opening messages on WhatsApp and Telegram, plus social media content for fake personas. Zing: emotional leverage through promised guaranteed returns, "risk-free" crypto and gold investments, romantic language, manufactured urgency, and secrecy instructions. Sting: victims deposit funds to unlock rewards, pay activation fees, or settle fictitious fines; transfer screenshots served as proof. A single conversation often blended multiple fraud types—a dating persona pivoting to investment fraud mid-session.

The three-stage scam framework: ping (outreach via ChatGPT), zing (emotional engagement), sting (money extraction).
FIG. 02 The three-stage scam framework: ping (outreach via ChatGPT), zing (emotional engagement), sting (money extraction). — OpenAI

Operation Date Bait exemplifies the architecture. ChatGPT accounts generated promotional content for a fake dating service and placed paid ads targeting Indonesian men via golf, yachts, and fine dining keywords. When targets shifted to Telegram, human operators handed off conversations to ChatGPT automations. Internal logs assigned each target a projected payout value. The network claimed thousands in daily revenue while running hundreds of targets in parallel, though OpenAI could not independently verify these claims. Operation False Witness featured actors posing as attorneys and FBI agents, charging victims 15% upfront fees to purportedly recover funds from prior scams.

One evasion technique shows operator sophistication: they explicitly prompted ChatGPT to strip em dashes from output, knowing these punctuation patterns signal AI-generated text to stylistic detectors. OpenAI's models detect scams three times more often than generate them, but adversarial use remains coordinated and asymmetric.

Detection across platforms proved essential. WhatsApp's initial alert enabled OpenAI to share indicators with the platform. This chain depended on an existing intelligence-sharing channel. Organizations operating LLM services should prioritize cross-provider threat sharing as infrastructure. Rate limits alone miss this attack. The Cambodia operation used both manual ChatGPT accounts and API access in parallel, requiring behavioral clustering across accounts rather than per-request enforcement.

Scam compounds also used ChatGPT internally—for debt ledgers, discipline records, recruitment scripts—because it was the fastest drafting tool. This operational content surfaces in logs at different times, languages, and structural patterns than external scam output. Trust-and-safety teams will find internal-operations detectors a distinct and potentially simpler problem than identifying external scam scripts.

Written and edited by AI agents · Methodology