LLM-Based Social Engineering Scams

OpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive:

The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, operators used dating personas to build trust before introducing fraudulent investment opportunities involving cryptocurrencies and spot gold trading. Other users engaged in lengthy romantic conversations with targets using fictitious identities, posed as representatives of online gambling platforms offering fake bonuses and winnings, or impersonated law enforcement agencies to tell targets they needed to pay fines for committing serious criminal offenses.

Although the narratives varied, users across the network consistently displayed the same underlying pattern of deceptive behavior. For example, they created and operated fake dating profiles, fictitious investment experts, and fraudulent law enforcement personas. They also generated images of forged documents, including passports, legal notices, stock-purchase confirmations, and gambling platform interfaces.

Posted on August 27, 2026 at 5:56 AM6 Comments

Comments

Q August 27, 2026 7:42 AM

This is what LLMs are good for, creating fakes.

It seems like LLMs have finally hit their stride. Empowering scammers with plausible nonsense to hoodwink the unwary.

I do wish that the “AI” promoters would stop trying to pretend LLMs can produce accurate and trustworthy things. LLMs can’t. But for fooling people into losing their life savings, yes indeed, LLMs have it, that is their strength.

Rontea August 27, 2026 10:33 AM

Modern cybercrime is an ecosystem. Financial fraud, social engineering, and human exploitation are increasingly intertwined. Disrupting the infrastructure—and sharing threat signals across platforms—is critical to blunting the impact of these networks before they adapt and resurface.

yet another bruce August 27, 2026 3:31 PM

The humans who run Social Engineering Scams like these are often kidnap victims forced to swindle others under threat of torture or starvation. They represent a tragedy on the same scale as the suffering of the scam victims themelves.

One glimmer of hope in this is that maybe the organized crime syndicates who run these schemes at scale will switch to LLM agents and stop the kidnappings.

Zsolt August 27, 2026 7:20 PM

OpenAI forgot to mention a couple of things.

  1. How long did this Cambodia-based based scam operation use ChatGPT before they shut them down?
  2. How much of a cut did OpenAI get from this scam operation (in ChatGPT subscription payments)?
  3. Why did OpenAI not see this on its own, why did they need WhatsApp to alert them?
  4. How are they going to detect and stop similar operations in the future?

I guess these are all rethorical questions … 🙁

Just a Thought August 27, 2026 11:16 PM

Regarding the Internet scams, hacks, crime/fraud in general, I always wondered as to why there isn’t a block/ban in place at the BGP level and at the level of a top country domain (any country) so that if your country (put any country name here) does not extradite criminals to my country when they steal/hack somebody in my country (put name of any country here) then the Internet to that entire country’s top Internet Domain is blocked.
This would require the .com domain to be archived and the USA would be required to switch all of the .com level domains to the already existing .us domain. Simply, each country has its own extension and it is up to each country, based on their Extradition Laws/Policies whether they want Internet connections/traffic/online business to be conducted with any other country. I do realize that in that case the VPN servers in another country would be off limit but something’s gotta give. These hard core thieves, high profile criminals have been hiding behind those non-extradiction laws since the inception of WWW and now with the very rapid growth and development of AI, it’s only gonna get worse.
Oh no, we cannot have that, it would hurt our saled/business…blah blah blah.
Why allow criminals from anywhere in the world to be able to connect to anyone in your country if their country isn’t gonna extradite them to your country after they’ve attacked/harmed/damaged/disabled/negatively impacted anything or anyone in your country. But but but but business is gonna suffer. It’s always business first – it makes me sick!

And now with AI/LLMs and the Quantum Computing being a reality in the probably not-so-distant future, it’s going to get uglyer than most can imagine.

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.