Inside the poipet scam compound: ping, zing, sting
Following a tip‑off from WhatsApp, OpenAI’s threat‑intelligence team traced a cluster of ChatGPT accounts to a sprawling criminal operation in Poipet, western Cambodia. The network did not limit itself to one scam flavour. Operators simultaneously ran romance fraud, fake investment platforms, illegal gambling promotion and impersonation of law‑enforcement agencies. The common thread was a three‑stage playbook the investigators mapped as ping, zing, sting:
- Ping: ChatGPT translated cold messages into multiple languages and generated social‑media posts to build fictitious dating profiles and expert personas.
- Zing: Emotional pressure and false promises – “risk‑free” crypto returns, urgent bonuses, confidential secrets – were scripted by the model to win trust.
- Sting: Victims were instructed to pay activation fees, fictitious taxes or regulatory fines, and to send screenshots as proof.
To support the deception, scammers produced AI‑generated images of forged passports, legal notices, stock‑purchase confirmations and entire cryptocurrency trading dashboards – all of which appeared convincing enough to extract thousands of dollars from individual targets. The network communicated with hundreds of victims, though the full financial damage could not be independently verified.
Beyond fraud: forced labour and human trafficking indicators
Perhaps more alarming, OpenAI found evidence that the same ChatGPT accounts were used to administer a system of debt bondage and labour coercion. Chat logs showed users creating job advertisements for “chatters” in Poipet, promising flights, accommodation, meals and work permits. Internally, the AI was employed to maintain spreadsheets tracking worker debts, salary deductions, disciplinary fines and visa overstays – a chilling administrative backbone for modern slavery.
References to detention, escape attempts and criminal liability for trafficked workers surfaced in the conversations. While OpenAI could not determine the fate of each individual, the patterns align closely with public reporting by Amnesty International and The Wall Street Journal. Organised scam networks in Southeast Asia are estimated to generate as much as 60 % of Cambodia’s GDP, underscoring why cross‑border crime and AI misuse can no longer be treated as separate problems.
How OpenAI turns its own models into a defence shield
OpenAI banned the identified accounts, shared threat indicators with industry partners and authorities, and hardened safeguards to block re‑entry. The company says its internal detection systems now flag and disrupt malicious activity at a striking ratio: OpenAI models are used to detect scams three times more frequently than malicious actors use them to create scams. In the Poipet case, the same models that were abused for fraud also analysed message patterns and flagged the network before it could cause even greater harm.
This defensive use of AI is not limited to English. The current suite of frontier models – including the GPT‑5.6 family (Luna, Sol, Terra) released on 9 July – powers real‑time monitoring across dozens of languages, a crucial advantage when criminal networks operate in Khmer, Chinese, Vietnamese and Burmese simultaneously.
The cost of deception: how many euro‑cents does a scam victim cost?
One reason AI‑driven fraud is exploding is its stark economics. Using the cheapest current frontier API tier, GPT‑5.6 Luna, a scam operation generating a full ping‑zing‑sting conversation of around 30 000 output tokens would pay roughly $0.036. Adding input prompts and image generation, the total per victim stays below $0.05 – at today’s exchange rate (approx. €0.046). Even targeting several hundred individuals would cost the criminals less than €15, while individual victims reportedly lost thousands of dollars. Luna’s official pricing ($0.20 per 1M input tokens, $1.20 per 1M output tokens, about €0.18 and €1.10 respectively) makes high‑quality social engineering accessible to anyone with an internet connection.
This cost asymmetry is exactly why the EU’s regulatory approach focuses not only on malicious users but on the duties of AI providers themselves – a framework that enters a new phase tomorrow.
Europe’s answer: the AI Act becomes directly enforceable on 2 August 2026
From 2 August 2026, the grace periods and voluntary codes of practice that governed general‑purpose AI models disappear. The European Commission’s AI Office and national authorities now have direct statutory power to enforce:
- Mandatory technical documentation and systemic‑risk rules for GPAI models like GPT‑5.6 or Claude Opus 5, forcing providers to continuously assess and mitigate the risk of their models being misused for organised crime.
- Transparency obligations under Article 50 – every user interaction with an AI chatbot must be clearly labelled, and synthetic text, audio or images must be machine‑readable and marked. Scammers deploying unlabelled deepfake dashboards and forged passports are therefore already violating EU rules, giving authorities a direct legal hook to pursue cross‑border cases.
- A requirement to report serious incidents and systemic risks to the AI Office, which could include the kind of criminal‑network abuse OpenAI has just disclosed. This effectively turns voluntary threat‑intelligence sharing into a compliance workflow.
For European users, the Poipet story is a warning: the same advanced AI models available legally in the EU through ChatGPT (with European servers and GDPR‑compliant data handling) can be weaponised by criminals elsewhere. The AI Act’s reach is territorial – any provider offering services in the EU must comply – but its real test will be whether the new reporting obligations help Europol and national cybercrime units dismantle networks faster than they can shift to open‑weight alternatives like Mistral’s Leanstral 1.5 or Meta’s Llama 4, which can be downloaded and run offline with no central oversight.
A dual‑use challenge that no law can solve alone
OpenAI’s takedown is as much a proof‑of‑concept for defensive AI as it is a revelation of systemic abuse. While the EU’s new rules establish a much‑needed accountability baseline, the cat‑and‑mouse game will persist. The Poipet network used ChatGPT for both victim‑facing scams and internal forced‑labour management – demonstrating that AI misuse is deeply entangled with serious organised crime. Dismantling such networks demands the kind of multi‑stakeholder intelligence exchange that OpenAI is now practicing, and that tomorrow’s EU enforcement framework is designed to encourage.
Can the new EU AI Act stop scammers from using AI?
Not directly. The Act forces AI providers to assess and mitigate systemic risks and to mark synthetic content. A scammer who downloads an unlabelled open‑weight model and generates fake documents breaks the transparency rules, but enforcing that against an overseas criminal compound is extremely difficult. However, the mandatory incident‑reporting and stronger cooperation channels with Europol will speed up takedowns and make it harder for large‑scale networks to operate untouched.
How can European users protect themselves from AI‑powered scams?
Be sceptical of unsolicited messages on WhatsApp or Telegram that mix romantic overtures with financial promises. Check whether images look computer‑generated (unnatural hands, blurry logos) and never send money to pay for “activation fees” or “taxes” to unlock rewards. The EU’s new transparency rules also mean legitimate AI services must tell you when you are chatting with a bot; scammers will not do that, which in itself is a red flag.
Does OpenAI’s disruption mean European law enforcement was involved?
OpenAI shared threat indicators with “relevant authorities” but did not name specific agencies. Europol’s European Cybercrime Centre (EC3) routinely coordinates with private partners on cases involving Southeast Asian scam compounds, and the new AI Act reporting channel will likely tighten this cooperation.