
A Cambodia based scam operation used ChatGPT to support multiple fraud styles, including investment and romance scams, gambling centric persuasion, and impersonation. The operation was disrupted, but the core lesson for business teams is how readily AI can help scammers run workflows that look plausible to victims.
What changed in the way scams are run
Instead of treating fraud as purely manual outreach, the criminals used an AI assistant to help draft and adapt communications across different scam themes. This makes it easier to keep messages consistent while still tailoring them for individual targets.
What UK businesses should do next
- Review your customer facing identity checks for emails, chat, and inbound account change requests, especially when requests are linked to money movement or sensitive data. The scam example combined investment and impersonation tactics, which is a common route to account and payment compromise in practice.
- Create internal playbooks for high risk messages that ask for urgent action, encourage secrecy, or direct customers to move funds quickly. Train support and sales teams to treat those signals as escalation triggers, regardless of whether the text looks polished.
- If your organisation uses AI tools for customer communications, put guardrails in place for content that could be interpreted as impersonation or instructions for payments. Ensure human review for any messages that could be used in fraudulent social engineering.
- Add verification steps for any channel where an agent may claim to be someone else, for example a request that appears to come from an executive or another department. The scam used impersonation as a distinct capability, so your controls should explicitly cover that pattern.
This is not about banning AI. It is about making your customer workflows harder to exploit, and ensuring people can recognise AI assisted social engineering when it shows up in support, sales, or onboarding.