ChatGPT Fuels Fraud in Cambodia

Did you know that an AI can build a complete fake identity in seconds?
ChatGPT was used by Cambodian crime syndicates to defraud Indian citizens.
We are not talking about a lone hacker in his bedroom: these were industrial fraud centers with dozens of operators, automated scripts, and victims selected with surgical precision.
OpenAI discovered it thanks to a WhatsApp alert and, upon investigating, found something far darker than expected: human trafficking included.

What they used to carry out the fraud was surprisingly simple to execute.
The operators of these centers in Poipet, a Cambodian city controlled by Chinese crime syndicates, asked ChatGPT for romantic seduction messages, fake stock confirmations, and fabricated legal notices. The AI drafted, translated, and personalized each message according to the victim, eliminating language errors that had previously given scammers away. The result was a conversation almost indistinguishable from a genuine one.
But the fraud went far beyond money.
Within those very chats with ChatGPT, records appeared of employee debts and salary deductions for internal penalties. Many of those “workers” were trafficked individuals, recruited through fake ads promising free flights and work visas to India. ChatGPT also drafted those flyers. The same tool that deceived external victims managed control over the real victims.
OpenAI blocked the accounts, but was unable to calculate the total financial damage.
What it did confirm is that the operation may have contacted hundreds of targets across different types of scams simultaneously. Several recorded conversations mentioned victims who had lost thousands of euros. OpenAI shut off the tap, but these centers have been operating for years and continue to expand.

Closing accounts does not close the problem.
These fraud centers in Southeast Asia survive every law enforcement crackdown because they adapt quickly, switch tools, and open new operations. The Cambodia case is just one more node in a network that is already eyeing South Asia and Africa.
AI already dominates global cybercrime.
INTERPOL published a study this week with data from 36 African countries: more than half of all cybercrime in Africa already uses artificial intelligence. The law enforcement agencies consulted confirm that AI now automates every phase of the attack, from initial reconnaissance to final extortion. This is not a future trend: it is the present reality of organized fraud at an industrial scale.
In Uganda, an AI-powered scam caused millions in losses.
Scammers used AI-generated audio and video to impersonate the image of a Ugandan public figure and promote a fraudulent investment. Victims saw and heard someone they trusted. There was no simple way to distinguish it from a real recording. That is the qualitative leap that changes everything.

You no longer need to be technical to run a sophisticated scam.
Anyone with access to a conversational AI can generate fake documents, personalized messages, and credible profiles in minutes. The barrier to entry for fraud has plummeted, multiplying the number of potential attackers exponentially.
Language no longer protects anyone.
In the past, a poorly translated message was the warning sign that saved you. Now AI corrects the accent, adapts the register, and eliminates the errors that used to give the deception away. It does not matter if the scammer is in Cambodia and you are in Madrid: the message will arrive perfect, in your language and with your tone.
Digital vigilance can never be lowered.
Verifying identities, being wary of offers that seem too good to be true, and cross-checking any unexpected contact are essential habits today, not optional ones for the future.
Protect yourself now
- ✓Be wary of job offers that promise free flights and visas.
- ✓Verify the real identity of whoever contacts you before responding.
- ✓Never share personal data in response to legal notices received via chat.
Could you tell the difference between a real message and one written by an AI?
Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.
Related articles
Nacata Security, reach out to us anytime
We are Nacata Security, get to know us
web: nacata.io
email: info@nacata.io
Phone: 919930793
LinkedIn: Nacata Security
Cyberattacks that have already happened and are confirmed: hacked companies, leaked data, services down after an attack, ransoms paid.
Real cases, with names and clear consequences, explained simply so anyone understands what happened and who it affected.
RATING
7.1
Who are we?
At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.
We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.
We’d be glad to get in touch with you for whatever you need.




