Skip to main content
OpenAI

February 1, 2025

Romance-baiting scam: AI-assisted pig butchering workflows

OpenAI banned accounts that appeared to originate in Cambodia and used AI to translate and generate romance, investment scam conversations.

Loading…

This case study was originally published in OpenAI’s February 2025(opens in a new window) report.

Actor

We banned a cluster of ChatGPT accounts that were translating and generating short comments in Japanese, Chinese, and English. This activity appears to have originated in Cambodia and was consistent with a romance and investment scam (otherwise known as “pig butchering”). Meta recently identified related activity(opens in a new window) on their platform that appeared to originate from a newly stood up scam compound in Cambodia.

Behavior

This network used our models to translate and generate short comments. The actors’ primary language appears to have been Chinese. The output was in a range of languages, notably Japanese and Chinese, but also English.

The actors used our models for two main activities. First, they would generate comments that were posted publicly on social media platforms including Facebook, X, and Instagram. Each social media account typically featured one or more profile pictures of a young woman: We assess that at least some of these profile pictures were copied from real models or influencers, rather than being AI-generated.

Most of the comments generated were posted in reply to real people’s social media posts. Some of the posts that the operators replied to were months or years old. This operation typically targeted men whose public profiles suggested they were aged over 40, often in the medical professions. The operation frequently replied to posts about golf, suggesting a deliberate targeting strategy. Occasionally, the scammers would post about political issues or current events.

Facebook comment generated for a romance and investment scam.

Facebook comment generated by this actor using our models, posted in reply to a comment about golf by a person who did not appear linked to this operation. The scam account’s profile picture is copied from a U.S. fashion and beauty influencer. The original post was over a month old by the time the scam account posted there.

X comment generated for a romance and investment scam.

Comment generated by our models, posted by a verified account on X in reply to a tweet by an account which did not appear linked to this scam. The account’s profile picture is copied from the same U.S. fashion and beauty influencer. The original tweet was almost six months old.

Second, and more frequently, the operators would generate short comments that resembled parts of an online conversation. This typically consisted of translating comments out of Chinese into a target language (Japanese or English), or from the target language back into Chinese. This is consistent with scammers using the model primarily to translate ongoing chats.

Sometimes, the accounts would ask the model to generate a reply in a certain tone of voice, such as a flirty young woman. Extensive biographical details were sometimes provided to guide the model in its answers, including the fake persona’s name, educational background, job, location, and hobbies. These biographies typically included the detail that the fake persona dabbled in online investment.

The scammers appear to have used a large number of different tools and platforms to engage their targets. Our investigation uncovered evidence of their using tools that included LINE, WhatsApp, X, Facebook, Instagram, a range of other messaging services, Apple’s “hide my email” function(opens in a new window), and cryptocurrency and foreign exchange platforms.

Completions

Based on our specific window into this activity, the scammers appear to have followed a common workflow in moving their targets from engagement to fraudulent investment:

  1. Public engagement: The scammers would make comments on social media posts by the target. These comments often ended in a question such as, “What do you think about [subject]?,” likely to increase the chance of engagement. In a handful of cases, they commented on politics, but more often, they talked about golf.
  2. Likely direct messaging: The scammers would then generate short, conversational comments. While we do not have full visibility into how and where these were deployed, the comments were consistent with a situation in which the scammer and target started exchanging direct messages.
  3. Secure messaging: Very soon, often within a few days, the scammers would generate messages that suggested moving to a more secure messaging app. Sometimes this would be justified by saying that the scammer did not trust social media; other times, it would be justified by a logistical excuse, such as saying that they were about to go somewhere they would not have access to social media.
  4. Romantic engagement: The scammers would write and translate increasingly affectionate and intimate messages. If the targets asked for photos of the “woman” they were chatting with, the scammers would make excuses.
  5. Financial engagement: The scammers would write and translate messages boasting about having made a large sum of money by online investment into foreign exchange, cryptocurrency, or gold. This would often be presented as the result of following the advice of a relative who worked in finance. The scammer would urge the target to start investing in the same way, and offer to guide them through the process.
  6. Fraud: The scammers would write and translate messages trying to convince the victim to transfer money into a trading app, and encourage them by talking up how much profit they were making. Any time the victim tried to withdraw their “profits,” the scammer would present an excuse, such as that a fee needed to be paid.

This pattern of activity is consistent with publicly available reporting(opens in a new window) on the way in which such scams typically work.

Impact

This activity appears to have included many false starts and failures. Some of the conversations that the scammers processed through our models ended with the target calling out the activity as a scam, or telling the scammer to leave them alone. We also identified posts by the scammers on social media that did not have any engagement at all.

However, some conversations referenced sums of thousands of dollars (or equivalent currencies) as the scale of individual transactions. Given the use that these operators made of our models, we do not have visibility into whether these financial transactions were conducted, but the conversational references do suggest that in at least some cases, the scammers managed to defraud their targets.

OpenAI’s policies strictly prohibit use of output from our tools for fraud or scams. We are dedicated to collaborating with industry peers and authorities to understand how AI is used in adversarial behaviors and to actively disrupt scam activities abusing our services. In line with this commitment, we have shared information about the scam networks we disrupted with industry peers and the relevant authorities.

Author

OpenAI