Select a theme from the list.
Insights

From our experts

Latest
Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination HubFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination Hub
Security Insight

OpenAI Shuts Down ChatGPT Accounts Supporting a Multi-Channel Scam Network

OpenAI Shuts Down ChatGPT Accounts Supporting a Multi-Channel Scam Network
Photo by Kindel Media on Pexels

OpenAI disrupted a coordinated collection of ChatGPT accounts associated with a scam operation in Poipet, Cambodia. The network allegedly used generative AI to operate fraudulent investment, romance, gambling and law-enforcement personas while translating messages, producing forged materials and managing internal administrative work.

News Date: 2026-08-05

OpenAI has banned a coordinated network of ChatGPT accounts linked to a Cambodia-based operation that supported several types of online fraud at the same time. The activity was associated with Poipet, an area previously connected to organized scam compounds and the exploitation of trafficked workers.

AI as Criminal Operations Software

The accounts reportedly used ChatGPT to create fictional identities, translate conversations and produce messages for investment, romance, gambling and law-enforcement impersonation schemes. Rather than relying on one script, the operators shifted between narratives depending on the victim and the platform being used.

Generative AI also supported the less visible administrative side of the operation. Accounts drafted internal notices and organized information involving salaries, debts, fines, immigration status, work permits and recruitment incentives. Some content advertised supposedly lucrative jobs in Poipet to users in Bangladesh and India.

The network created fake dating profiles, investment experts and government representatives. It also generated materials resembling passports, legal notices, trading confirmations and gambling interfaces. Initial contact commonly occurred through messaging platforms, followed by a period of trust building and an eventual demand for an investment deposit, activation payment or fabricated legal fine.

OpenAI investigated the activity with Meta-owned WhatsApp. The financial scale remains uncertain, but internal conversations indicated that the network may have contacted hundreds of targets. References to individual losses reaching thousands of dollars were not independently verified.

Defending Against Scaled Impersonation

  • Financial institutions should monitor sudden transfers to newly created cryptocurrency or investment accounts.
  • Messaging platforms should connect behavioral signals across related accounts rather than reviewing each conversation in isolation.
  • Businesses should train employees to verify unexpected legal, recruitment and payment requests through independent channels.
  • AI providers should continue combining account-level enforcement with intelligence sharing across social and messaging services.

The Broader Significance

This case shows that criminals do not need a specialized malicious model to benefit from artificial intelligence. A general-purpose assistant can improve translation, maintain numerous personas and reduce the cost of producing convincing documents.

In my view, the main risk is not that AI invents a completely new form of fraud. It makes existing fraud easier to operate across languages, platforms and victim groups. Effective disruption will therefore require cooperation among AI companies, banks, telecommunications providers, social networks and law enforcement rather than relying on any single platform to identify the complete campaign.

Talk to our team →

Latest

Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026Public Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinySep 8, 2026PEEP Turns Trusted Browsers Into Persistent Command CentersSep 8, 2026BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingSep 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path