AI & TechArtificial IntelligenceBigTech CompaniesCybersecurityDigital MarketingNewswire

ChatGPT Ranked in Top 10 Most Impersonated Brands for Phishing

Originally published on: July 26, 2026
▼ Summary

– ChatGPT entered the top 10 most impersonated brands in phishing attacks for the first time in Q2 2026, according to a Check Point study.
– A fake “ChatGPT Plus payment failed” email was observed in June, designed to steal full credit card details.
– Microsoft remained the most impersonated brand, accounting for 23% of all phishing attempts, followed by LinkedIn.
– Technology was the most targeted industry, with other real cases including fake storefronts and login pages for brands like Michael Kors and PayPal.
– Check Point recommended using AI-powered detection and consolidating security platforms to prevent brand phishing.

For the first time, ChatGPT has landed in the top 10 of the most impersonated brands for phishing attacks, according to a new report from Check Point covering the second quarter of 2026. This marks a significant shift in cybercriminal strategy, as attackers increasingly target the tools people rely on daily.

One notable example observed in June was a fake “ChatGPT Plus payment failed” email. The message was crafted to appear as an official OpenAI billing notice, directing victims to a fraudulent page designed solely to harvest full credit card details. Check Point described the inclusion of OpenAI’s flagship product as “a strong signal of where attacker attention is heading next.”

The cybersecurity firm added, “As AI tools move from novelty to daily habit for millions of people managing subscriptions, payments, and work tasks through them, they become just as attractive a target as any bank or tech giant. Expect AI platforms to keep climbing this list in future quarters.”

Microsoft remains the most impersonated brand overall, accounting for 23% of all phishing attempts. That share is nearly double that of LinkedIn, the second-most targeted brand,which Microsoft also owns. Google, Apple, and Amazon round out the top five, collectively driving more than half of all phishing activity.

Check Point defines brand phishing as an operation where a scammer impersonates a trusted company through email, a fake website, or both, aiming to steal login credentials, payment details, or personal information. Real-world cases from Q2 2026 ranged from fake payment failure alerts to full replica online stores, counterfeit login pages, and malware disguised as software updates.

The report also highlights that technology was the most targeted industry overall, followed by social networks and banking. Other notable cases included a cloned Michael Kors store that replicated the entire checkout process, a fake UNIQLO storefront in a country where the brand does not even operate, and a suspicious PayPal login page featuring a warped logo that appeared AI-generated.

To help organizations defend against these threats, Check Point published recommendations on July 23. Key strategies include stopping phishing messages inline before they reach an inbox, rather than relying on detection after damage is done; using AI-powered detection to catch brand impersonation, business email compromise, credential harvesting, QR code phishing, and AI-generated attacks with a level of accuracy manual review cannot match; consolidating email and workspace protection across Microsoft 365, Google Workspace, and collaboration tools into a single platform to reduce operational complexity; and automating investigation and response so security teams can resolve real threats faster.

(Source: Infosecurity Magazine)

Topics

brand phishing attacks 95% chatgpt impersonation 92% check point report 90% microsoft phishing 88% payment failure scams 87% ai tool targeting 85% top impersonated brands 84% technology industry 82% phishing prevention 80% ai powered detection 78%