Operation “Wrong Number”: AI-assisted task scam
OpenAI banned accounts that likely originated in Cambodia and used AI to support scam workflows targeting people in the UK.
This case study was originally published in OpenAI’s June 2025(opens in a new window) report.
Actor
We banned ChatGPT accounts that were generating short recruitment-style messages in English, Spanish, Swahili, Kinyarwanda, German, and Haitian Creole. These messages offered recipients high salaries for trivial tasks, such as liking social media posts, and encouraged them to recruit others. The operation appeared highly centralized and likely originated from Cambodia.
Using AI-powered translation tools, we were able to investigate and disrupt the campaign’s use of OpenAI services swiftly.
Behavior
The majority of the network’s comments involved translation tasks. They used ChatGPT to translate conversational sentences between Chinese and several other languages, most notably English, Spanish, Kinyarwanda, Swahili, German, and Haitian Creole. These tasks typically alternated between translating an incoming message into Chinese and translating a response from Chinese back into the original language.
A subset of these messages resembled cold-call job advertisements, offering high hourly pay for minimal work. One such message was distributed via SMS to what appeared to be a random set of UK mobile phone numbers, one of which belonged to an OpenAI investigator. We have dubbed this operation “Wrong Number,” in honor of the initial SMS.

SMS randomly sent to an OpenAI investigator, generated using ChatGPT.
The threat actors appeared to rely on multiple messaging platforms. The initial SMS directed recipients to engage via WhatsApp, where responders were then routed to a “mentor” on Telegram. Some activity also referenced the BonChat messaging app. Early, introductory messages via these channels did not appear to have been generated using our models. They consisted of routine messages which would likely apply to every conversation.

WhatsApp message sent as a follow-up to the SMS. This message does not appear to have been generated by our models.
Many of the translation tasks involved communications that purported to come from representatives of alleged “employer” companies. The same company names repeatedly surfaced across numerous ChatGPT conversations in scope of this investigation. These included Hyesung Advertising(opens in a new window) and Lightning Shared Scooter Co (LSSC)(opens in a new window). Public reporting has identified Hyesung and LSSC as alleged task schemes. While we have not independently verified the nature of these entities, our investigation found that messages supposedly coming from them were generated by Chinese-speaking ChatGPT users, likely operating from Cambodia.
Completions
The companies this network claimed to represent spanned a broad range of industries, from stock trading, to scooter rentals, to selling social media likes. One clear red flag was the offer to pay more than $5 for a single TikTok like; by contrast, our manual review of online marketplaces showed that some sellers of social media likes charge less than $10 for 1,000 likes.
By combining off-platform indicators with internal observations, we identified a recurring workflow pattern. To promote broader understanding of this tactic and simplify its classification, we describe this pattern as: the ping (cold contact), the zing (generate enthusiasm), and the sting (extract money):
- The ping (cold contact): The network generates content intended for cold outreach, typically offering unusually high wages for minimal work or promising high returns on stock-market investments. These offers include high pay for simple tasks, such as liking social media posts, or lucrative investment opportunities.
- The zing (generate enthusiasm): The network translates conversations, likely between the operator and their “employees.” These exchanges include logistical details about tasks but are frequently interspersed with motivational messages about earnings and potential bonuses.
- The sting (extracting money): The network generates and/or sends content that pressures the “employee” or “investor” to contribute money to unlock larger rewards. This takes several forms, including an initial “deposit,” cryptocurrency purchases, and “handling fees.”

Example of a cold-call message generated using ChatGPT and distributed by this network. The message was sent to eight phone numbers simultaneously, none of which were in the recipient’s contact list. One recipient left the group immediately.

Telegram message from the network to a potential victim, instructing them to purchase £20 worth of cryptocurrency and transfer it to an unnamed merchant.
Public reporting(opens in a new window) suggests that some of these companies operated by charging new recruits substantial joining fees, then using a portion of those funds to pay existing “employees” just enough to maintain their engagement. This structure is characteristic of task scams(opens in a new window).
Impact
It’s difficult to quantify this network’s true reach given our limited visibility. However, off-platform reports(opens in a new window) and conversations in which “employees” demanded refunds indicate that at least some individuals paid these alleged employers. We also observed genuine users defending the companies on social media, suggesting a degree of real-world engagement.