OpenAI Scam Operations Report October 2025
OpenAI has disrupted several scam networks originating in Cambodia, Myanmar, and Nigeria that utilized ChatGPT to scale and refine online fraud operations. While these actors used AI to increase the efficiency of existing scam playbooks, OpenAI reports that ChatGPT is used by the general public to identify and avoid scams up to three times more often than it is used to facilitate them.
The "Ping, Zing, and Sting" Fraud Pattern
OpenAI identifies a consistent three-stage pattern used by the disrupted scam networks to defraud targets:
- The Ping (Cold Outreach): Scammers scatter AI-generated or manual content across the internet and messaging services, often utilizing social media ads to initiate contact.
- The Zing (Emotional Manipulation): Once a target responds, scammers generate enthusiasm for a lucrative opportunity or fear of financial loss to manipulate the target's emotions.
- The Sting (Extraction): The final stage involves convincing the target to hand over money or sensitive personal information.
AI as a Scaling Tool for Existing Playbooks
Most disrupted operations did not create new AI-native fraud methods but instead integrated AI into existing scam playbooks to improve scaling and efficiency. Key uses of ChatGPT included translation, drafting correspondence, creating social media content, and conducting basic research.
Investment Fraud Operations
Scam operations likely originating in Cambodia and Nigeria posed as fake investment firms. These actors used AI to:
- Create fraudulent websites and online advertisements.
- Generate content for inauthentic social media accounts posing as trading experts.
- Translate and generate correspondence to entice victims into fictitious trading platforms.
Operational Management in Myanmar
In Myanmar, OpenAI disrupted a scam center that used ChatGPT not only for fraudulent schemes but for internal business operations. The model was used to organize schedules, draft internal announcements, manage financial accounts, and assign dormitory and desk allocations. Some operators even used the model to inquire about the criminal penalties associated with online scams.
Advanced AI Application and Persona Development
While many scammers performed simple tasks, some operations exhibited higher complexity in their use of AI to create convincing facades.
Synthetic Personas and Conversational Continuity
A Cambodia-based operation used ChatGPT to generate detailed biographies for fake investment experts and employees. Scammers then directed the model to write messages in these specific characters' voices. In some instances, they fed the model actual messages from targets and asked ChatGPT to continue the conversation while maintaining the fake persona.
Orchestrated Group Dynamics
Another Cambodia-origin operation used bulk-sent SMS messages to invite targets to WhatsApp groups. Once inside, targets witnessed orchestrated conversations between multiple accounts—including an "investment expert" and several investors with varying experience levels—all generated by the scammers. These conversations were translated from Chinese in single blocks to simulate a vibrant trading community.
Targeting and Compliance Evasion
An investment scam operation likely originating in Nigeria requested step-by-step advice from ChatGPT on how to reach wealthy individuals in Latin America via social media ads, how to mask their location, and how to avoid platform restrictions by asking the model to review ad content against a platform's public terms of service.
Evasion Tactics and Industry Collaboration
Scam networks are persistent and frequently attempt to evade detection after disruptions. OpenAI has observed several obfuscation techniques:
- Stylistic Changes: Some Cambodia-based operations directed the model to remove em-dashes from outputs to avoid AI-detection signals.
- Fabricated Explanations: After WhatsApp banned specific investment groups, one Cambodia-linked operation generated messages claiming the bans were the result of false reports by competitors to maintain credibility with targets.
OpenAI emphasizes the importance of industry-wide information sharing, citing collaborations with Meta to investigate and enforce actions against shared threat actors.