OpenAI Disrupts Operation Wrong Number AI-Assisted Task Scam

OpenAI has disrupted a centralized scam operation, dubbed ‘Operation Wrong Number,’ which used ChatGPT to facilitate multi-language recruitment and translation for fraudulent task schemes. The operation leveraged AI to scale cold outreach and manage conversations with victims across various global regions.

AI-Powered Translation and Recruitment

Operation Wrong Number used ChatGPT primarily as a translation tool to bridge the gap between Chinese-speaking operators and victims speaking English, Spanish, Swahili, Kinyarwanda, German, and Haitian Creole. The network's workflow involved translating incoming messages from victims into Chinese and translating the operators' responses from Chinese back into the target languages.

Beyond translation, the network used ChatGPT to generate short, recruitment-style messages. These messages offered high salaries for trivial tasks, such as liking social media posts, and encouraged recipients to recruit others.

The "Ping, Zing, and Sting" Workflow

OpenAI identified a recurring three-stage tactical pattern used by the threat actors to defraud victims:

  1. The Ping (Cold Contact): The network generates content for cold outreach, promising lucrative investment opportunities or unusually high wages for minimal work (e.g., liking social media posts).
  2. The Zing (Generate Enthusiasm): The network translates conversations between operators and "employees," providing logistical details about tasks and motivational messages regarding potential bonuses and earnings.
  3. The Sting (Extracting Money): The network generates content to pressure victims into paying money to unlock larger rewards. This includes demands for initial deposits, cryptocurrency purchases, or "handling fees."

Infrastructure and Execution

The operation appeared to be highly centralized and likely originated from Cambodia. The threat actors utilized a multi-platform messaging strategy to move victims through the funnel:

  • Initial Contact: Distributed via SMS (the "Wrong Number" SMS sent to an OpenAI investigator served as the catalyst for the investigation).
  • Engagement: Victims were directed from SMS to WhatsApp.
  • Management: Responders were eventually routed to a "mentor" on Telegram.
  • Other Platforms: Some activity also referenced the BonChat messaging app.

Targeted Entities and Red Flags

The network claimed to represent various companies across industries such as stock trading, scooter rentals, and social media engagement. Specifically, the investigation found messages generated by Chinese-speaking users claiming to represent Hyesung Advertising and Lightning Shared Scooter Co (LSSC), both of which have been identified in public reporting as alleged task schemes.

A primary indicator of fraud was the extreme disparity in pay offered. The network offered more than $5 for a single TikTok like, whereas manual reviews of online marketplaces showed some sellers charge less than $10 for 1,000 likes.

Impact and Reach

While the total reach of the network is difficult to quantify, OpenAI observed evidence of real-world financial loss. Off-platform reports and conversations where "employees" demanded refunds indicate that some individuals paid the alleged employers. Additionally, the presence of genuine users defending these companies on social media suggests the operation achieved a degree of real-world engagement.

Sources