New AP/Frontline Investigation: U.S. Tech Powers Boom in Transnational Scam Operations Out of Myanmar

New AP/Frontline Investigation: U.S. Tech Powers Boom in Transnational Scam Operations Out of Myanmar

New AP/Frontline Investigation: U.S. Tech Powers Boom in Transnational Scam Operations Out of Myanmar

The rules were explicit: scammers got exactly four days to manipulate each target into falling in love. And there was no shortage of potential victims.

Safeer Mohammed Koorimannil, a man trafficked to a scam compound in Myanmar, spent his workdays online posing as Ella, a 28-year-old Singaporean woman. On a typical shift, he told reporters, he juggled conversations with more than 100 marks across dozens of fake profiles at once, while supervisors patrolled the rows of desks carrying electric batons.

Over just one month, Koorimannil personally targeted roughly 50,000 people across at least 17 countries, according to internal records he smuggled out and shared with the Associated Press. His pool of potential victims included a widowed tailor in Kurdistan, a pastry chef in Turkey, a sheep farmer in Kyrgyzstan, Iraqi soldiers, a Russian engineer, a building painter in Germany, a port officer in Argentina, an Indonesian student, a security guard in Poland and a dairy farmer in the Republic of Georgia.

All of this mass fraud was made possible by software built on artificial intelligence models from major U.S. tech companies—tools scammers are now abusing to target victims at an unprecedented speed and scale. Speaking to the AP from his home in southern India in his native Malayalam, Koorimannil said: “Everyone there is just a part of a robotic machine.”

A joint AP/Frontline investigation has found that U.S.-developed technology is driving a transformation of the global scam industry, playing an unrecognized central role in the industrialization and cross-border spread of fraud that has not been fully documented until now.

Watchdogs note that while these companies have the technical capacity to do far more to block misuse, they lack legal, regulatory and financial incentives to crack down on a crime the U.S. Federal Trade Commission estimates cost American victims nearly $200 billion in losses in 2024 alone.

Most public scrutiny of scam-enabling technology has focused on the social media platforms where victims first encounter scammers, but the investigation found the exploited infrastructure powering fraud originates much farther upstream. U.S. technology is embedded at every step of the digital supply chain connecting scammers to targets: from AI models baked into new tools that streamline scam workflows and create convincing fake content, to satellite internet that lets scammers evade global internet crackdowns, to mainstream internet providers that route fraud traffic from Myanmar’s lawless border regions straight to the phones and laptops of millions of potential victims.

The AP found no evidence that any of these U.S. companies have acted illegally themselves. Even so, the widespread abuse of their tools and infrastructure at Myanmar’s scam compounds, documented by AP and Frontline, raises new questions about how vigorously companies enforce their own terms of service—rules that already prohibit illegal activity, and in most cases explicitly ban fraud.

Core Investigation Findings

Working with global security nonprofit C4ADS and anti-trafficking group International Justice Mission, the probe uncovered:

  • U.S.-built AI models, most notably OpenAI’s ChatGPT and Google’s Gemini, are being used to develop custom scam software that lets operators work seamlessly across dozens of languages, monitor captive workforces, and target victims globally. Blockchain analysis by TRM Labs, conducted at the request of AP/Frontline, found scammers who use these AI-powered tools have generated tens of millions of dollars in illicit revenue.

  • A sophisticated global internet infrastructure supports Myanmar’s scam economy, relying on services from major U.S. firms including Cogent Communications, AT&T, DigitalOracle, among others. An AP analysis of more than 200,000 device connection records found 1 in 5 data signals from devices at four Myanmar scam compounds linked to U.S.-sanctioned entities was routed through a U.S.-registered company.

  • Elon Musk’s satellite internet company Starlink is the largest internet service provider in Myanmar, and remains a top connectivity provider for scam centers—despite public pressure from U.S. Congress and a widely publicized crackdown last fall, according to device data, public records and interviews.

  • At least 25 new scam compounds have been built deep inside Myanmar’s interior since last fall’s high-profile crackdown on fraud hubs along the Thai border, new satellite imagery confirms. AP analysis of device and satellite data found scammers at 13 of these new outposts used Starlink IP addresses to access the internet between early March and late May of this year.

Investigation Methodology

The joint AP/Frontline probe was built on: tens of thousands of leaked internal scam center files, videos and photos; a collaborative analysis of AI misuse with C4ADS; a review of 12 months of device connection data from four U.S.-sanctioned-linked Myanmar scam compounds; and interviews with 58 scam victims and 36 current and former scammers from 19 countries.

Cybersecurity experts say internet providers, AI developers, and Starlink all could do more to block scammer abuse—but face little motivation to act. “If there’s no downside to letting this continue, if there’s no cost to facilitating scamming, why would a company spend a dollar to stop it?” said Sascha Meinrath, the Palmer Chair in Telecommunications at Penn State University. “This problem is identifiable, it’s addressable—at least partially—but it costs money. Right now, the cost for companies to facilitate scamming is zero.”

Global Regulatory Split on Scam Prevention

Outside the U.S., the cost of inaction for tech companies is starting to rise. The United Kingdom, European Union, Australia, and Singapore have all implemented new rules requiring firms to do more to prevent scams, or face heavy financial penalties. In Washington, by contrast, lawmakers and officials have only asked U.S. tech companies to voluntarily cooperate to cut scammers off from American infrastructure.

In November, U.S. Attorney for the District of Columbia Jeanine Pirro launched the Scam Center Strike Force, a dedicated unit targeting transnational scam compound operations. During a four-day enforcement action in May, the strike force partnered with Meta, SpaceX, Google and other firms to disrupt more than 1.4 million fraudulent social media and email accounts, block malicious IP traffic, seize unlicensed satellite internet terminals, and take down servers and hosting infrastructure tied to Southeast Asian scam networks.

“We will not allow criminal organizations to weaponize our own infrastructure against us or devastate the life savings of hardworking families,” Pirro said in an email to the AP. “Our message is clear: we will find you, we will stop you, and we will protect the American people.”

Industry Responses

Both OpenAI and Google said they maintain robust proactive programs to disrupt scammers from misusing their AI tools. Starlink did not respond to detailed requests for comment on this investigation.

U.S. internet service providers emphasized that their privacy-by-design architecture means they cannot view the content moving across their networks or track end user activity, a limitation that restricts their ability to proactively monitor for abuse. All firms said they respond to valid abuse reports and cooperate with law enforcement. No company agreed to disclose specific customer information, citing privacy rules, but several confirmed they had taken concrete action after receiving questions from the AP for this investigation.