Fraud Alert: 'Ping', 'Zing' and 'Sting', The New Scam Playbook
Not so long ago, spotting a scam was fairly straightforward. A badly worded message, an email that just looked off (like a prince from a far, far away place announcing he was donating his wealth via email without even knowing your name!), a photo or logo that clearly was not real — any of these was usually enough to make people suspicious. That advantage is disappearing steadily and very fast with the easy availability of artificial intelligence (AI) tools. Most importantly (and a worrying factor), you don't need specialised knowledge or even basic training to use AI tools to become a fraudster or cybercriminal. AI does most of the heavy lifting for you.
AI is now helping fraudsters communicate more naturally, create convincing fake identities and produce documents and images that can look remarkably authentic. AI as technology itself is not the problem. The danger comes when organised criminals use AI to make old-fashioned fraud more believable and easier to run at scale.
OpenAI recently gave us a genuinely unsettling look at how this plays out in practice. The company said it shut down a Cambodia-based scam operation that had been using ChatGPT across several types of fraud — romance scams, fake investments, gambling schemes and even people pretending to be law enforcement officers. AI was doing the writing and translating, building the fake personas, churning out promotional material and generally keeping the whole operation ticking along.
What makes this case stand out is that these criminals were not sticking to one script. “The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, operators used dating personas to build trust before introducing fraudulent investment opportunities involving cryptocurrencies and spot gold trading. Other users engaged in lengthy romantic conversations with targets using fictitious identities, posed as representatives of online gambling platforms offering fake bonuses and winnings, or impersonated law enforcement agencies to tell targets they needed to pay fines for committing serious criminal offences,” OpenAI said.
So, someone might first get approached on a dating app. Weeks of what feels like a genuine, warm conversation later, the ‘stranger’ casually mentions an investment opportunity — crypto, maybe, or spot gold. Somebody else gets offered a tempting lottery bonus. Someone else again gets a frightening message from ‘the police’, insisting they owe a fine or penalty for some serious offence they supposedly committed.
The story changes every time. The goal never does: win your trust, or hit an emotional nerve and then get you to send money or hand over sensitive details.
OpenAI describes the pattern in three neat stages — the ping, the zing and the sting. The ping is just the opening contact. The zing is whatever emotional hook gets under your skin — excitement, greed, fear, affection or urgency. Take your pick. And the sting is the moment you are finally convinced or pressured into transferring money, paying some fee, or handing over information.
Honestly, this is one of the more useful ways to understand how modern scams actually work.
That first message often looks entirely harmless. A simple ‘hello’. A job offer. Someone saying hi on a dating app. An investment tip. A warning about some legal trouble you supposedly have. The real danger only kicks in once the criminal starts building a relationship with you, or starts turning up the pressure.
Take a romance scam as an example. Rather than asking for money straight away, the fraudster will often spend weeks just chatting — messages that read as grammatically clean, personal, warm and genuinely convincing. AI can translate on the fly and generate replies that sound completely natural, even trustworthy, like a real-life charming prince or princess.
That same technology lets one operator from the gang run several fake identities at once, without much effort at all.

In the Cambodia case, OpenAI found scammers had built fake dating profiles, invented investment ‘experts’ and fabricated police personas — right down to generating convincing images of passports, legal notices, even stock-purchase confirmations, plus fake interfaces designed to look exactly like real gambling or crypto platforms. “Although the narratives varied, users across the network consistently displayed the same underlying pattern of deceptive behaviour. For example, they created and operated fake dating profiles, fictitious investment experts and fraudulent law enforcement personas. They also generated images of forged documents, including passports, legal notices, stock-purchase confirmations and gambling platform interfaces.”And that is exactly where most of us need to unlearn an old habit: stop judging authenticity by how something looks.
Just remember, a polished-looking document proves nothing. A convincing photo proves nothing. Good English proves nothing about whether the person on the other end is trustworthy. Even a website that looks exactly like your bank, your stockbroker, or a government office can still be completely fake.
Cybercriminals know this and also understand very well how easily people let their guard down the moment something looks official. The digital arrest scam is the biggest example of this.
Investment fraud works the same way. A stranger builds credibility first — chatting about markets, sharing ‘successful’ trades, sending screenshots of made-up profits. Once you trust them, they will suggest a small deposit to start. Then, more fake profits appear and the amounts they ask for start climbing.
An employee from an IT company ‘invested’ some money through an app. After the app displayed ‘bumper returns’, he liquidated other investments, including fixed deposits in the name of his spouse and daughter and obtained personal loans to invest through the app. He invested lakhs of rupees. After a few days, when he tried to withdraw the money, now in crores of rupees as per the app, all the contacts who had encouraged him and promised ‘bumper returns’ vanished, and the app also disappeared from the Play Store.
That is the sting, right there.
There is another point worth sitting with. AI doesn't need to invent some brand-new type of scam to do damage — it just makes the old ones faster, cheaper and more convincing.
OpenAI's own wider research backs this up: criminals are simply layering AI onto tools that already existed — websites, social media, apps, messaging apps — and getting a lot more mileage out of them.
So, What Can Ordinary People Actually Do?
Start with one simple rule: the moment money, fear, or strong emotion enters an online conversation, just slow down.
If someone you have never met in person suddenly wants you to invest, don't send a single rupee while that conversation is still live. Stop. Go and verify the person and the investment independently, using contact details you found yourself, not ones the stranger handed you.
If an online partner starts bringing up crypto, gold trading, forex, or any ‘opportunity’, treat that as a serious red flag straight away. No genuine person or entity can assure guaranteed, risk-free returns — not ever. In fact, market regulator Securities and Exchange Board of India (SEBI), strictly prohibits registered investment advisors and market players from guaranteeing returns, accuracy, or risk-free investments.
If someone claiming to be a police officer, a court official, or a government authority threatens to arrest you or fine you, don't panic and don't engage. End the call or chat and get in touch with that authority through their official website or a publicly listed number instead. A logo, an ID card, or a profile photo doesn't make the threat real.
The same goes for ‘free’ money or a lottery. Fake bonuses, prizes, lotteries or jackpots are built to create urgency. If you are asked to pay an activation fee or a processing charge before you can get your ‘winning money’, that is the scam making its appearance out in the open.
Never share one-time passcodes (OTPs), passwords, personal identification numbers (PINs), card details or remote-access permissions with anyone who contacted you out of the blue. And don't send screenshots of your banking transactions just because someone insists they need ‘proof’.
One more thing worth remembering: cybercriminals often ask you to keep things secret. That request alone should make you pause. Speak with a family member, a friend, anyone — a second opinion is often exactly what breaks the emotional grip a scammer has built up.
And don't assume you will spot an AI-assisted scam just because you are on the lookout for typos or clunky phrasing. That old tell is becoming a lot less reliable by the day. In fact, over the years, we have found highly educated and smart people falling victim to a scam quite easily.
So, a better approach altogether is to focus on behaviour rather than presentation.
Who actually contacted you? How did you meet? Why do they want money? Why does it have to happen right now? Why can't you check this independently? Why are you being told to keep it quiet? Why do they need access to something they really shouldn't?
Those questions will get you further than staring at a photo, photo ID or display profile (DP) trying to decide if it's AI-generated.
OpenAI said it couldn't independently confirm the total financial losses tied to the Cambodia network, though the operation appeared to have reached hundreds of targets, with some conversations referencing individuals who had lost thousands of dollars. The company banned the accounts involved and shared its findings with industry partners and authorities.
But the bigger warning here goes well beyond this one case.
The next scammer who gets in touch with you might not sound like a cybercriminal at all. The profile might look entirely genuine. The conversation might feel warm and personal. The document might look completely official. The website or the app might look thoroughly professional.
Which is exactly why getting better at spotting fake photos or ‘perfect’ messages is no longer the answer. What matters is getting better at recognising pressure and secrecy, noticing promises that sound too good to be true and requests for money or information that should not be handed over so easily.
The moment you notice those signs, stop. Check independently. Ask someone you trust. And if the story can't survive a few minutes of someone else looking it over, it should not get your money or information either.
Stay Alert. Stay Safe!
