ChatGPT disrupted a Cambodia-based operation using AI for Human Trafficking & Cybercrime

Actor was operating inside a Poipet-linked operation that blended romance, investment, and impersonation scams — and left traces of forced labor.
In a new threat disruption report, OpenAI says it dismantled a coordinated network of ChatGPT accounts tied to a Cambodia-based criminal operation running investment, romance, gambling, and law enforcement impersonation schemes at scale.
The investigation began earlier this year following a lead from peers at WhatsApp, and OpenAI says it has since shared threat signals with industry partners and relevant authorities.
The Actor: A Diversified Scam Compound
OpenAI banned what it describes as a coordinated network of ChatGPT accounts that very likely originated in Cambodia, and was likely operating in or around Poipet, a city in Banteay Meanchey province. Poipet has been repeatedly linked in public reporting to online scam compounds and trafficking operations.
What stood out technically was not a single novel exploit, but operational diversification. The report notes organized groups rarely stick to one playbook. This network was running multiple fraud types simultaneously.
How ChatGPT Was Weaponized
The network did not use the model to hack infrastructure. It used it as a force-multiplier for social engineering and operations:
- Persona factory: Creating and supporting fake online personas, including fake dating profiles, fictitious investment experts, and fraudulent law enforcement personas.
- Localization at scale: Generating and translating messages sent to targets on WhatsApp and Telegram, plus researching dating profile material to make personas believable.
- Creative and forgery support: Generating promotional content for fraudulent schemes, including a fake cryptocurrency trading interface and AI-generated images promoting bogus investments.
- Document forgery: Users generated images of forged documents, including passports, legal notices, stock-purchase confirmations, and gambling platform interfaces.
- Back-office ops: Like past scam networks OpenAI has disrupted, a subset also used ChatGPT for administrative work, including drafting internal announcements, translating messages between staff, and documenting matters related to recruitment, immigration status, working conditions, and employee discipline.
The Kill Chain: Ping, Zing, Sting
OpenAI maps the group's behavior to a recurring three-stage social engineering pattern it has seen before:
The ping (outreach), the zing (generate emotion), and the sting (extract money).
1. The Ping: Translate and generate outreach on messaging platforms, create social media content, and research dating profiles.
2. The Zing: Build trust with emotional pressure. In this case, operators used dating personas to build trust before introducing fraudulent investment opportunities involving cryptocurrencies and spot gold trading. Other vectors included lengthy romantic conversations with fictitious identities, fake gambling bonuses, and impersonation of law enforcement telling targets they needed to pay fines for serious criminal offenses. Common tactics included promises of guaranteed returns and "risk-free" investments, romantic language, instructions to keep conversations secret, and urgent deadlines.
3. The Sting: Extract payment. Victims were instructed to make deposits to unlock rewards, pay activation fees, settle fictitious fines, and provide screenshots of transfers as proof.
The Darker Layer: Human Trafficking Indicators
Beyond fraud, OpenAI flagged content suggesting links to human trafficking and forced criminality.
The network generated social media ads for "chatter" jobs in Poipet promising flights, accommodation, meals, visas, and work permits. Internally, accounts maintained records of employee debts, salary deductions, disciplinary fines, and loan repayments, and translated discussions about immigration status, work permits, visa overstays, and recruitment incentives.
Some conversations also referenced apparent detention, escape attempts, and potential criminal liability for people who had been trafficked and forced to work in scam operations. OpenAI notes it cannot independently determine individual circumstances, but says the activity is consistent with extensive public reporting on organized crime groups in Southeast Asia recruiting workers with promises of legitimate employment before trapping them in debt bondage and coercion.
Tool to check if Image is generated using ChatGPT
OpenAI says it banned the ChatGPT accounts associated with the operation, shared relevant indicators with industry partners and authorities, and took steps to make it harder for the actors to regain access.
ChatGPT has created an online utility to check if a content is generated by its model.

The full scale of financial losses is unknown, but based on the scammers' own communications, the operation may have interacted with hundreds of targets, with references to individual victims losing thousands of dollars, claims OpenAI says it cannot independently verify.
The case, OpenAI argues, reinforces two trends for defenders: scam networks are now highly diversified, operating multiple fraud schemes simultaneously rather than adhering to a single type, and the boundaries between online fraud, organized crime, and human trafficking are increasingly blurred. Effective disruption, the report concludes, has to target not just the victim-facing prompts, but the criminal organization behind them.