Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Online Fraud. Show all posts

OpenAI Disrupts Cambodia-Based Scam Network That Used ChatGPT for Global Fraud Campaigns


The use of ChatGPT by OpenAI has enabled it to dismantle a coordinated scam operation based in Poipet, Cambodia which used ChatGPT for multiple online fraud schemes, including investment scams, romance scams, illegal gambling promotion, and impersonating police officers. According to the company, the network operated in an area that has historically been associated with organized cybercrime, scam compounds, and human trafficking. 


Using ChatGPT, OpenAI asserted that the operation was capable of creating convincing fake online identities, generating multilingual messages, translating conversations, and creating promotional materials for fraudulent campaigns using ChatGPT. Furthermore, the AI tool was used in order to streamline the internal administrative tasks of the criminal operation, such as drafting announcements, maintaining employee records, tracking salary deductions, visa statuses, recruitment incentives, and financial obligations.

In a statement, OpenAI said that the investigation was initiated after WhatsApp provided intelligence that led to the identification of coordinated ChatGPT abuse. As the company notes, the network employed AI models for both generating fake online personas and messages, translating conversations, producing promotional content, and managing day-to-day operations, thus demonstrating how generative AI can significantly enhance cyber fraud efficiency and scale. 

There were several noteworthy aspects of the campaign, including social media advertisements advertising "chatter" jobs in Poipet. Specifically, the advertisement targeted job seekers in India and Bangladesh with salaries of $800, performance bonuses, free flights, lodging, meals, work permits, and Cambodian visas for one year. This offer is believed to have been made to lure victims into scam compounds, where forced labor is often practiced. 

OpenAI said its investigation, in collaboration with WhatsApp, resulted in the removal of a coordinated cluster of ChatGPT accounts, which originated from Southeast Asia. The criminal group was operating multiple fraud schemes simultaneously in contrast to one fraud scheme at a time. The victims were contacted via messaging platforms such as WhatsApp and Telegram by individuals who presented themselves as dating profiles, investment advisors, gambling platform representatives, or law enforcement officials using fabricated dating profiles.

In order to build trust with victims, these personas were designed to persuade them to invest in cryptocurrencies or gold trading schemes, to pay fabricated activation fees, to claim fake winnings, or to pay bogus legal fines. An attacker uses forged passports, legal notices, investment confirmations, fabricated payment screenshots, as well as interfaces for gambling platforms to convince victims that their transactions are legitimate. 

According to OpenAI, the scammers employed a ping-zing-sting method to establish contact with potential victims, gain their trust through extended conversations, and ultimately pressure them into making financial payments. A scam compound operated by organized criminal groups was located in Poipet, a Cambodian city widely known for hosting scam operations. 

In the region, there has been a sustained pattern of large-scale cyber fraud and human trafficking operations, in which victims are lured with false job offers and then coerced into conducting online scams against people across the globe. 

There was also evidence of links between the operation and human trafficking, as some artificial intelligence generated content suggested workers were recruited through deceptive job offers, before their passports were confiscated and they were forced into scams. Moreover, investigators discovered internal conversations indicating that some workers recruited through these advertisements may have been victims of human trafficking. 

According to OpenAI, the records referenced employee debts, disciplinary fines, immigration problems, visa overstays, and even discussions about detentions, escape attempts, and criminal liability, illustrating the exploitative nature of scam compounds. However, OpenAI said internal communications indicated the network may have targeted several fraud campaigns and hundreds of victims, with some conversations referring to individual losses worth thousands of dollars, although the full financial impact has not yet been established. 

In light of the disruption, generative artificial intelligence is playing an increasingly important role in organized cybercrime, enabling threat actors to automate content creation, social engineering, and operational management in unprecedented quantities. The findings also aligned with a recent INTERPOL assessment, which indicated that artificial intelligence has increasingly been utilized throughout the cyberattack lifecycle, from reconnaissance and phishing to extortion and evasion. 

While law enforcement agencies are continuing to target scam compounds across Southeast Asia, experts caution that these operations continue to expand into other regions, causing concern about the global reach of AI-assisted cyber fraud.

ED Charge Sheet Maps Sriki's Darknet Crypto Laundering Network

 

The Enforcement Directorate (ED) has filed a sprawling 3,500-page prosecution complaint before a special PMLA court in Bengaluru, laying out what it calls a “sophisticated network” blending high-level hacking, darknet operations, cyber extortion and multi-crore cryptocurrency laundering. The charge sheet names serial hacker Srikrishna Ramesh, alias “Sriki”, crypto trader Robin Khandelwal, businessman Sunish Hegde, a private IT firm and two of its officials as accused in a case that spans breached government portals, crypto exchanges and online gaming platforms. 

From government portals to poker sites: the alleged breach chain 

According to the ED, Sriki, described as a highly skilled software programmer, exploited vulnerabilities in national and international cryptocurrency exchanges, online gaming and poker platforms, and corporate servers. He is accused of breaching the Karnataka government’s e-procurement portal and siphoning off about ₹11.5 crore in two transactions, besides hacking the Unocoin exchange and several major online poker platforms. The agency alleges that stolen virtual digital assets such as Bitcoin were then “layered” and offloaded through multiple international crypto platforms to obscure their origin.

The prosecution complaint details how Robin Khandelwal allegedly acted as a key conduit, converting illicit digital assets into fiat currency through over-the-counter deals and crypto-trading channels. Investigators claim Sunish Hegde conspired with Sriki to extort money from hacked companies by negotiating with them after the breaches, while Infinzy Solutions and two officials are accused of facilitating the transfer of funds stolen from a poker site. The three main accused were arrested in May and are in judicial custody at Parappana Agrahara Central Prison, with the ED citing digital evidence, blockchain analysis and bank records to support its case. 

 Darknet links and ongoing money trail probes 

The 3,500-page document reportedly sketches connections between Sriki’s hacking operations and darknet marketplaces, building on earlier investigations that noted his use of the darknet to purchase drugs using Bitcoin. About ₹7 crore of the ₹11.5 crore siphoned from the e-procurement portal has been traced, with around ₹2 crore formally attached and another ₹5 crore frozen in various bank accounts; the remaining ₹4.5 crore is still being tracked. The ED says its probe into the movement and use of the alleged proceeds of crime is continuing, even as the prosecution complaint functions as the equivalent of a police charge sheet under PMLA. 


For regulators, the Sriki case underscores how advanced technical skills, weak spots in government and corporate platforms, and an evolving crypto ecosystem can intersect to create large-scale financial crime. The dossier highlights the need for stronger blockchain forensics capacity, tighter oversight of informal crypto-OCT channels, and better coordination between cybercrime units, the ED and financial intelligence agencies. As India’s digital economy expands, securing e-governance portals, exchanges and gaming platforms is becoming not just an IT issue, but a core element of financial integrity and national cybersecurity strategy.