Operation False Witness: OpenAI Disrupts AI-Powered Recovery Scam

OpenAI has disrupted a fraudulent operation, dubbed "Operation False Witness," which used ChatGPT to impersonate U.S. law enforcement and legal professionals to target fraud victims. The operation, likely originating in Cambodia and linked to Chinese-led criminal networks, utilized AI to generate professional-sounding legal content and deceptive credentials to extract money from vulnerable individuals.

Execution of the Recovery Scam

The malicious actors employed a three-stage workflow—Ping, Zing, and Sting—to identify, groom, and defraud targets.

1. Initial Outreach (Ping)

Scammers used ChatGPT to create promotional content for at least six fictitious law firms. This content was distributed via social media and online advertisements to attract individuals seeking to recover financial losses from previous scams. Indicators of fraud included:

  • Lack of state bar licensing.
  • Use of incongruous web domains.
  • Non-existent street addresses for contact information.
  • Instructions to communicate exclusively via messaging apps.

2. Trust Building (Zing)

To establish credibility, the actors used ChatGPT to emulate the professional tone of specialized attorneys. They created lawyer personas with profile pictures that were either stolen from social media or AI-generated. In some instances, the same attorney identity was reused across different fake law firms. The operation also created a website impersonating the FBI’s Internet Crime Complaint Center (IC3) to mislead victims.

3. Financial Extraction (Sting)

Once trust was established, scammers used ChatGPT to draft messages requesting advance payments. These fraudulent charges included:

  • A 15% "service fee" required before the release of purportedly recovered funds.
  • Deposits to "activate" accounts.
  • Various "consultation fees."

Victims were instructed to send these payments via cryptocurrency and provide screenshots of the transactions as proof.

Role of AI in the Fraud Workflow

ChatGPT was integrated into multiple stages of the operation to enhance the perceived legitimacy of the scammers.

Communication and Translation

The most frequent use of ChatGPT was for translating messages between the scammers and their targets on private messaging apps. Specifically, actors requested the model to write replies in "American English" or in the style of a lawyer to maintain a professional facade.

Creation of Deceptive Materials

A subset of the accounts used OpenAI models to generate forged documents intended to discourage victims from seeking outside help and to bolster the scam's authenticity, including:

  • Fake attorney registration records.
  • Forged bar association membership cards (e.g., New York State Bar Association).
  • Bogus confidentiality agreements.

Impact and Attribution

While OpenAI cannot independently verify the total financial loss, input data suggests individual victims may have been defrauded of thousands of dollars. The operation specifically targeted vulnerable populations, including the elderly, by exploiting their emotional distress over previous financial losses.

Both the FBI and at least one impersonated law firm have issued public alerts regarding this specific scam. OpenAI has banned the associated accounts in accordance with policies that strictly prohibit the use of its tools for fraud or scams.

Sources