AI Writes Fluent Scam Messages Now. Does That Make Them More Effective?
The advice people have heard most often about suspicious messages is to look for spelling mistakes and awkward phrasing.
That advice used to work well, because many of the people sending scam messages were not native speakers, so the text carried traces you could catch.
What has changed is that tools now exist which write fluent Thai without the user knowing any Thai at all.
The United Nations Office on Drugs and Crime published a report on this in September 2025, recording that phishing-as-a-service kits are increasingly integrating AI modules to automatically generate tailored phishing content.
Rather than relying on generic or poorly crafted templates, the report states, criminal actors can prompt large language models to produce persuasive, professional-sounding messages that replicate legitimate communications from banks, government agencies or commercial platforms.
"When the text contains no errors to catch, advice about spotting spelling mistakes has quietly stopped working."
The report also records that evidence from scam centres operating in Southeast Asia indicates language models are actively being used to conduct multilingual conversations with victims, with syndicates reportedly using AI-driven scripts capable of holding simultaneous conversations in different languages, an operation that would previously have required a trained team of multilingual staff.
To conceal where the operation is based, the report adds, some tools even automatically detect and suppress unintended language outputs, for instance ensuring Chinese text does not appear in scams targeting non-Chinese speakers.
For Thai readers the relevant line is direct: these tools permit English-speaking operators to convincingly phish victims in Thai, Vietnamese or Japanese.
Source: https://www.unodc.org/roseap/uploads/documents/Publications/2025/UNODC_Report_Emerging_threats_-_The_intersection_of_criminal_and_technological_innovation_in_the_use_of_automation_and_AI.pdf
Evidence From the Developers Themselves
What lifts this above speculation is that the companies building these models publish reports on the accounts they detect and shut down.
OpenAI's report of October 2025 records that in the previous three months the company disrupted scam networks that likely originated in Cambodia, Myanmar and Nigeria.
Its most important conclusion is that all of the scam operations identified and banned that year primarily used AI as a scaling and efficiency tool, which typically meant using the models for translation, to write messages, and to create content for social media.
A concrete example: one likely Cambodia-origin operation used the models to generate detailed biographies for fake investment experts and fictitious employees of fake trading firms, then asked the model to write social media messages in those characters' voices.
Often, the report notes, the operators fed in messages they appeared to have received from their targets and asked the model to continue the conversation as the fake persona.
In another case the company banned a scam centre highly likely located in Myanmar that used the models both to generate content for its fraudulent schemes and to run day-to-day business tasks, including organising schedules, drafting internal announcements, assigning desk and dormitory allocations, and managing financial accounts. Some operators, the report records, asked about the criminal penalties for people caught conducting online scams.
The detail most relevant to anyone trying to spot AI text is this: the report records that scam operations likely originating in Cambodia directed the model to remove em-dashes from its outputs.
The em-dash is one of the marks people use to guess that text was machine-written. That operators are instructing the model to strip it out shows the tells people rely on are being closed off one by one.
Source: https://cdn.openai.com/threat-intelligence-reports/7d662b68-952f-4dfd-a2f2-fe55b041cc4a/disrupting-malicious-uses-of-ai-october-2025.pdf
The Question That Matters Most: Is It Actually More Effective?

The widespread assumption is that because AI writes more fluently, the scams must work better.
It sounds reasonable. When somebody actually measured it, the result was otherwise.
A field experiment by researchers at the Technical University of Berlin and partner institutions sent real phishing emails to 7,741 recipients and measured what share of each type produced a click.
The results were these. Untargeted mass emails achieved a click rate of 3.9 per cent. Emails automatically personalised by a language model achieved an average of 10.0 per cent.
But personalised emails written by humans achieved the highest rate of all at 24.2 per cent, 2.4 times higher than the language-model version, and the researchers report that this difference is statistically significant.
Comparing like with like at the same level of targeting makes it clearer still. Mass emails written by a language model achieved 3.7 per cent, while mass emails written by humans achieved 4.1 per cent. The machine-written side did slightly worse.
The researchers state that this effect is consistent, regardless of whether the generic emails are written by humans or generated by language models.
So what did change? The answer is cost. The researchers record that the cost of personalisation using language models is minimal, at 0.03 dollars per email, and that a budget of only 150 dollars was required to send personalised emails to all 3,310 users for whom publicly available information existed.
In plain terms, AI has not made scam messages better at persuading. It has made individually targeted scams, which previously required a person to research and write each one, into something that can be done to thousands of people at once for the price of a few cups of coffee.
Source: https://mlsec.tu-berlin.de/docs/2026-sec.pdf
What AI Still Cannot Do Instead of People
One paragraph in the UNODC report is rarely repeated, yet it matters a great deal for understanding where this is heading.
The report records that reliance on AI does not eliminate the role of persons trafficked for forced criminality, and that scam centres continue to recruit or coerce individuals with specific language skills.
It gives two reasons: the limitations of language models in maintaining cultural nuance, and the preference of criminal groups for direct human interaction where persuasion is critical.
That finding lines up exactly with the experiment in the previous section. When it comes to the point of genuinely persuading someone, humans still do it better.
Source: https://www.unodc.org/roseap/uploads/documents/Publications/2025/UNODC_Report_Emerging_threats_-_The_intersection_of_criminal_and_technological_innovation_in_the_use_of_automation_and_AI.pdf
Cases in Thailand
The UNODC report records Thai cases as well, citing the Cyber Crime Investigation Bureau of the Royal Thai Police as its source.
It records that in late 2024 and early 2025, Thai and Cambodian authorities dismantled two major scam networks using AI-powered deepfake technologies.
The first involved Thai nationals arrested in Chiang Mai who managed a network backed by a Chinese crime group, combining romance fraud with investment fraud.
The method was AI-generated video calls featuring synthetic faces with real-time facial animation and lip-sync, used to build trust with victims in Thailand, Vietnam and the United States, who were then directed to invest in a fake platform displaying fabricated financial returns.
The report records that officers arrested 20 suspects across 11 provinces, seizing digital evidence including automated customer-relationship dashboards, mobile devices preloaded with scam scripts, and fake app interfaces.
The second case involved Thai nationals running a scam centre in Poipet, Cambodia, arrested for applying AI voice cloning and real-time deepfake video technology to impersonate law enforcement and financial authorities.
The tool they used allowed them to overlay the facial images of real police officers, scraped from publicly available sources, over their own faces during a live video call.
Source: https://www.unodc.org/roseap/uploads/documents/Publications/2025/UNODC_Report_Emerging_threats_-_The_intersection_of_criminal_and_technological_innovation_in_the_use_of_automation_and_AI.pdf
What the Thai Police Recommend
If spelling is no longer a signal, and voices and faces can both be faked, the question is what the public can actually do.
Police Colonel Neti Wongkularb, Deputy Commander of the Technology Crime Suppression Division under the Central Investigation Bureau, told Thai PBS Verify that one AI-based scam tactic used in 2025 was voice impersonation, which had already been in use for several months.
The pattern is that scammers often begin with the pretence that they have changed their phone number, asking the victim to delete the old number and save the new one they are calling from. They then engage in casual conversation, usually hanging up first and waiting a day or two before calling a second time.
Victims are typically deceived into transferring tens of thousands to hundreds of thousands of baht, or more where the scammers succeed.
The advice given is very simple. Politely hang up the call from the unfamiliar number immediately, even if the caller claims to be your child, a relative or someone you know. Then call back using the original number you already have saved, and ask whether they called you.
Source: https://www.thaipbs.or.th/verify/en/article/content/8455
Lessons for Thailand
First, the advice about spotting spelling mistakes should be retired. Today's tools write fluent Thai without the user knowing any Thai, and continuing to rely on that signal may leave careful people feeling safer than they are.
Second, do not simply replace it with a new signal drawn from the text itself. The OpenAI report shows that once a tell becomes publicly known, operators instruct the model to avoid it. Text-based tells will always have a short shelf life.
Third, what still works, and will keep working, is verification through a channel you already know. This is exactly what the Thai police recommend: do not reply through the channel the scammer chose, but go back to the one you already had. It works even if the voice and face are faked perfectly, because it does not depend on judging what is real.
Fourth, in policy terms, what AI changes is scale and cost, not persuasive power. A figure of 0.03 dollars per message means individually targeted fraud is no longer expensive. Defences therefore have to be built for far greater volume, not for cleverer messages.
Finally, this connects back to people. The UNODC report records that AI has not removed the need for staff in scam centres, because where genuine persuasion is required, criminal groups still choose humans. Which means the trafficking that supplies those centres will not disappear either.
References
Czybik, S., Kouam, A., Heubl, S., Nold, D., & Rieck, K. (2026). A large-scale study of personalized phishing using large language models. Technische Universität Berlin. https://mlsec.tu-berlin.de/docs/2026-sec.pdf
OpenAI. (2025). Disrupting malicious uses of AI: An update, October 2025. https://cdn.openai.com/threat-intelligence-reports/7d662b68-952f-4dfd-a2f2-fe55b041cc4a/disrupting-malicious-uses-of-ai-october-2025.pdf
Thai PBS Verify. (2026, January 19). AI clone and deepfake: Beware of 2026 new scam tactics as voices and faces of your family may not be real. https://www.thaipbs.or.th/verify/en/article/content/8455
United Nations Office on Drugs and Crime. (2025). Emerging threats: The intersection of criminal and technological innovation in the use of automation and AI. https://www.unodc.org/roseap/uploads/documents/Publications/2025/UNODC_Report_Emerging_threats_-_The_intersection_of_criminal_and_technological_innovation_in_the_use_of_automation_and_AI.pdf
Good knowledge should not stay in the library. It should be used to build a safer world.
Follow us at www.crimesci.com
Contact info@crimesci.com
#HubofKnowledge #CenterforCrimeScience #CrimeScienceWeekly
#วิทยาการอาชญากรรม #AI #อาชญากรรมออนไลน์ #Deepfake







