OpenAI dismantled a Cambodia-based fraud operation running from Poipet that exploited ChatGPT to execute investment scams, romance schemes, gambling fraud, and law enforcement impersonation attacks. The company terminated a coordinated network of ChatGPT accounts linked to the Southeast Asian operation.

The Poipet scam network leveraged OpenAI's chatbot to automate and scale multiple fraud vectors simultaneously. Threat actors used ChatGPT to generate convincing text for fake investment pitches targeting victims with promises of high returns. Romance scammers deployed the AI to craft personalized messages in phishing campaigns designed to build trust before requesting money. The operation also ran gambling fraud schemes where ChatGPT assisted in creating fake betting platforms and promotional materials.

Law enforcement impersonation represented another attack vector. Scammers used the chatbot to draft threatening messages mimicking police or government agencies, pressuring victims into wire transfers under false pretenses.

OpenAI's enforcement action reflects growing abuse of large language models in fraud operations. ChatGPT's natural language generation capabilities enable threat actors to operate at scale without hiring multiple human writers, reducing operational costs while maintaining message authenticity. The platform's initial guardrails proved insufficient to catch this particular network until manual investigation and account linkage analysis identified the coordinated behavior.

The disruption included account terminations and API access revocation for the identified users. OpenAI did not disclose the total number of compromised accounts or estimated victim count, though Poipet's history as a fraud hub suggests the operation likely affected thousands of targets across multiple countries.

This incident underscores a persistent challenge for AI platform operators. While OpenAI maintains abuse prevention systems, sophisticated threat actors continue finding workarounds. Organizations relying on ChatGPT or similar services face inherited risks when malicious users weaponize these tools for fraud.