# ChatGPT Was Working for the Scam Compounds. OpenAI Just Fired It.


The city of Poipet sits on Cambodia's border with Thailand, and for the past several years it has been synonymous with something darker than its casinos and border crossings suggest. Scam compounds — operations that sometimes use trafficked labor — have turned this corner of Southeast Asia into a fraud industrial zone. Investment cons, romance scams, fake gambling platforms, cops-impersonating schemes. All running in parallel, in dozens of languages, at scale.


OpenAI this week confirmed what many researchers suspected: the compounds found ChatGPT useful. The company said it banned a coordinated network of accounts originating from Poipet, accounts that were being used to generate content for multiple fraud schemes simultaneously. The operation wasn't one scam. It was a franchise.


## What AI Actually Bought Them


The specific use cases matter more than the headline. These weren't people asking ChatGPT to "write me a phishing email." The scam compound model is more sophisticated than that, and the AI integration reflects it.


Romance scams — often called "pig butchering" in the industry, from the Chinese *sha zhu pan*, a reference to fattening a pig before slaughter — require sustained, believable conversation over weeks or months. A trafficked worker sitting at a desk in Poipet might be running twenty "relationships" simultaneously with targets in the United States, Europe, or Japan. The language barrier alone used to be a real friction point: awkward phrasing, inconsistent tone, odd hours. AI removes all of that. It drafts messages that read like a real person wrote them. It maintains character. It scales.


Law enforcement impersonation is the faster-burn variant. Victims receive calls or messages claiming to be from Interpol, the FBI, or local police. There's a warrant, or a compromised account, or a drug shipment found in their name. The resolution involves moving money. These scripts benefit from AI too — they need authoritative, jurisdiction-specific language. "Your Social Security number has been suspended" hits differently when the message doesn't have typos.


Gambling fraud closes the loop: lure someone in with romance, get them to a fake platform, show them early wins, then drain their account when they try to withdraw.


## The Poipet Detail Is Not Incidental


OpenAI specifically named the city, which is worth sitting with. Poipet has been flagged by the UN Office on Drugs and Crime, by Reuters, by researchers at the Australian Strategic Policy Institute. Human rights groups have documented cases of workers being trafficked there under promises of legitimate tech jobs, then forced to run scams under threat of violence. The Chinese government has intermittently pressured Cambodia to crack down; Cambodia has made periodic arrests that don't seem to slow the operation materially.


This is not a lone hacker or a small crew. The Poipet scam ecosystem is closer to a call center industry with a forced-labor component and zero legal accountability. The people running these operations have physical infrastructure, organizational hierarchy, shift schedules, and now, apparently, ChatGPT licenses.


The AI adoption makes sense economically. Hiring workers — even trafficked workers — who speak fluent English, Japanese, or German is a constraint. AI removes the constraint. A single operator can run English-language and Mandarin-language cons in the same shift. The personalization that used to require a skilled social engineer now comes from a prompt.


## OpenAI's Move and Its Limits


Banning the accounts matters. It raises friction. It forces the operation to find workarounds — VPNs, account farms, alternative models. That's a real cost imposed on real adversaries.


But let's be honest about what it doesn't do. The compounds are not dependent on OpenAI's API. Alternative large language models — some open-weight, some hosted by providers with less rigorous abuse monitoring — are widely available. The moment one provider bans an account, the operation can pivot. The technical sophistication required to switch from ChatGPT to another model is low. The scripts, the workflows, the target lists — those don't disappear.


What OpenAI's announcement does accomplish, beyond the direct disruption, is producing a public record. The company described the fraud categories, the operational footprint, the geographic origin. That feeds law enforcement intelligence. It feeds the NGO and researcher community. It's useful even if the specific accounts banned are replaced by tomorrow.


The harder problem is that detecting AI-generated romance messages is genuinely difficult at scale. Platforms where these conversations happen — WhatsApp, Telegram, dating apps — don't have the same abuse surface visibility that OpenAI has over its own output. The locus of the harm moves downstream.


---


## HackWire Analysis


This is one of the cleaner examples of a trend that's been building for eighteen months: AI as a force multiplier for fraud, not for novel attack vectors, but for scaling old ones.


The pig-butchering model was already a multi-billion dollar criminal industry before ChatGPT. The FBI's IC3 reported over $4.5 billion in investment fraud losses in 2023 alone, with romance-to-crypto funnels accounting for a disproportionate share. What AI changes is the operator-to-victim ratio — how many targets a single bad actor can credibly run at once.


What the coverage of this incident is largely missing is the forced labor angle. When we talk about "scam operators" in Poipet, we're often talking about operations where the people typing the messages had their passports confiscated. AI doesn't just help the bosses scale — it also means they can extract more output from fewer workers, or replace workers they have to pay with purely automated pipelines. The humanitarian and the cybersecurity stories are the same story.


For defenders, the near-term implication is clear: the "bad English" heuristic for detecting scam messages is dead. Grammatical errors were never reliable indicators, but they were *something*. AI fluency removes that signal entirely. Consumer awareness campaigns that rely on "look for typos" need an update. Organizations running anti-fraud training — banks, elder care networks, anyone with a vulnerable population — should retire that guidance now and replace it with behavioral pattern recognition: unsolicited contact, urgency escalation, requests to move money off-platform.


Payment rails are where this ends, and that's where intervention still has leverage. No AI-generated romance script succeeds without a money movement step. Crypto exchanges, wire transfer services, and payment apps that haven't invested in behavioral friction for first-time large transfers are still the soft underbelly.


OpenAI made the right call. The compounds will adapt. The race is between their adaptation speed and the detection infrastructure that makes each pivot more expensive.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)