3 Sources
[1]
Be careful where you click -- ChatGPT joins Microsoft, Google in most-impersonated brands online
* OpenAI now accounts for 1.1% of all tracked brand impersonations, ranking top 10 * Microsoft and LinkedIn still account for a joint 34.2% of all impersonations * Basic cybersecurity hygiene can prevent many attacks New research from Check Point has revealed ChatGPT is becoming increasingly targeted in brand phishing attempts, with the company now appearing in the top-10 list alongside heavy hitters like Microsoft, Google and Apple. Though ChatGPT only accounted for 1.1% of all tracked brand phishing attempts, this marks the first time it's appeared in the top-10 and reflects continued growth for attackers. It sees a similar number of attacks to PayPal (1.3%), WhatsApp (1.4%) and Facebook (1.9%), but at present, it's far behind Microsoft, which when combined with its LinkedIn subsidiary, accounts for more than a third (34.2%) of all tracked brand impersonations. ChatGPT is growing as an impersonated brand One example from the second quarter of this year saw fake ChatGPT Plus payment failure emails copying OpenAI's branding, but directing victims to a fraudulent payment page to maliciously collect their payment information. As for Microsoft, fake support pages warned customers that they needed to update Office for security fixes, but the download actually installed malware on victim devices. Attacks on OpenAI are fairly ironic, because it's likely to company's own AI tools (among plenty of others) that actually helped attackers to write many of the attacks at lightning pace. Overall, tech companies were targeted most, followed by social media platforms in a similar vein, and then banking apps. Despite fluctuations in terms of which brands are targeted and how campaigns look, the general attack vector remains unchanged, with cybercriminals targeting vulnerable users and emphasizing urgency to trick people out of sharing information, credentials and payment details. Security experts warn potential victims to be weary of clicking on unknown URLs and opening unexpected communications, as well as to protect their accounts with passkeys and secure multi-factor authentication (MFA). Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
[2]
Microsoft Tops Q2 2026 Brand Phishing Attacks as Cybercriminals Target Trusted Brands: Check Point Research
A notable shift this quarter was the first appearance of Open AI's ChatGPT among the top ten most impersonated brands, marking a clear signal that AI tools are now firmly on cybercriminals' radar. Check Point Research (CPR) a pioneer and global leader of cyber security solutions released its Brand Phishing Ranking for Q2 2026. These latest findings reveal that Microsoft continues to remain the most impersonated brand, accounting for 23% of all brand phishing attempts during the quarter -- nearly double the next closest brand. The findings show that cybercriminals continue to exploit the trust users place in widely used technology, social networking, banking and now AI platforms to steal credentials, payment details and personal information. In Q2 2026, LinkedIn ranked second at 11.6%, followed by Google at 6.7%, Apple at 5.8% and Amazon at 5.2%. Together, the top five impersonated brands accounted for more than half of all brand phishing activity tracked this quarter, underscoring how attackers are focusing on a small group of globally recognised platforms that people use and trust every day. A notable shift this quarter was the first appearance of Open AI's ChatGPT among the top ten most impersonated brands, marking a clear signal that AI tools are now firmly on cybercriminals' radar. As AI platforms become part of daily workflows for subscriptions, payments and workplace tasks, they are becoming attractive targets for phishing campaigns in the same way as established technology and financial brands. By industry, Technology remained the most impersonated sector, followed by Social Networks and Banking, reflecting attackers' continued focus on platforms that hold users' identities, professional relationships and money. Omer Dembinsky, Data Research Manager at Check Point Research said, "Brand phishing is entering a new phase where attackers are not only exploiting trust in household technology names, but also moving quickly toward the AI platforms people are beginning to rely on every day. As generative AI enables criminals to create more credible emails, cloned websites and fake digital experiences at scale, organisations must shift from reacting after compromise to preventing these threats before users ever engage with them." One campaign impersonated ChatGPT Plus through a fake subscription payment failure email that led victims to a page designed to steal full credit card details. Another campaign used a lookalike Michael Kors online store that replicated the shopping journey, including browsing, cart and checkout, to capture payment information under the appearance of a legitimate purchase. Attackers also created a fake UNIQLO regional storefront in a market where the brand does not officially operate, with disconnected social media icons serving as one of the indicators of fraud. In another case, a fake Apple iCloud login page used Apple's logo and branding, while a non-functional sign-in button suggested the page may still have been under testing before a broader campaign. The report also documented a near-identical PayPal login page with a distorted logo, which may indicate the use of AI-generated assets, and a fake Microsoft support page that pushed an urgent Office security update but delivered a disguised executable file instead. Why Brand Phishing Is Becoming Harder to Spot Brand phishing works because it transfers trust from a familiar organisation to a fraudulent message or website. Across Q2 2026 cases, attackers used urgency, realistic branding, lookalike domains, broken buttons, mismatched links and subtle visual flaws to lower user suspicion and drive faster action. Generative AI is also changing the economics of brand phishing by helping attackers produce more convincing emails and fraudulent websites at scale, making both the volume and sophistication of these attacks likely to grow. With generative AI lowering the barrier to creating convincing fake websites, emails and digital experiences, brand phishing is becoming harder to detect and easier to scale. As trust becomes the primary target, organisations must assume these attacks will continue to grow in both volume and sophistication.
[3]
Microsoft Remains Most Impersonated Brand in Q2 Phishing as ChatGPT Emerges as New Target
Check Point Research today released its Brand Phishing Ranking for Q2 2026. These latest findings reveal that Microsoft continues to remain the most impersonated brand, accounting for 23% of all brand phishing attempts during the quarter -- nearly double the next closest brand. The findings show that cybercriminals continue to exploit the trust users place in widely used technology, social networking, banking and now AI platforms to steal credentials, payment details and personal information. In Q2 2026, LinkedIn ranked second at 11.6%, followed by Google at 6.7%, Apple at 5.8% and Amazon at 5.2%. Together, the top five impersonated brands accounted for more than half of all brand phishing activity tracked this quarter, underscoring how attackers are focusing on a small group of globally recognised platforms that people use and trust every day. A notable shift this quarter was the first appearance of Open AI's ChatGPT among the top ten most impersonated brands, marking a clear signal that AI tools are now firmly on cybercriminals' radar. As AI platforms become part of daily workflows for subscriptions, payments and workplace tasks, they are becoming attractive targets for phishing campaigns in the same way as established technology and financial brands. By industry, Technology remained the most impersonated sector, followed by Social Networks and Banking, reflecting attackers' continued focus on platforms that hold users' identities, professional relationships and money. Omer Dembinsky, Data Research Manager at Check Point Research said, "Brand phishing is entering a new phase where attackers are not only exploiting trust in household technology names, but also moving quickly toward the AI platforms people are beginning to rely on every day. As generative AI enables criminals to create more credible emails, cloned websites and fake digital experiences at scale, organisations must shift from reacting after compromise to preventing these threats before users ever engage with them." Top 10 Most Imitated Brands in Phishing - Q2 2026 * Microsoft - 22.6% * LinkedIn - 11.6% * Google - 6.7% * Apple - 5.8% * Amazon - 5.2% * Adobe - 3.8% * Facebook - 1.9% * WhatsApp - 1.4% * PayPal - 1.3% * ChatGPT - 1.1% Real-World Phishing Campaigns Observed in Q2 2026 The Q2 2026 report highlights a wide range of brand phishing techniques, from fake payment failure notices to replica online stores, fraudulent login pages and malware disguised as software updates. One campaign impersonated ChatGPT Plus through a fake subscription payment failure email that led victims to a page designed to steal full credit card details. Another campaign used a lookalike Michael Kors online store that replicated the shopping journey, including browsing, cart and checkout, to capture payment information under the appearance of a legitimate purchase. Attackers also created a fake UNIQLO regional storefront in a market where the brand does not officially operate, with disconnected social media icons serving as one of the indicators of fraud. In another case, a fake Apple iCloud login page used Apple's logo and branding, while a non-functional sign-in button suggested the page may still have been under testing before a broader campaign. The report also documented a near-identical PayPal login page with a distorted logo, which may indicate the use of AI-generated assets, and a fake Microsoft support page that pushed an urgent Office security update but delivered a disguised executable file instead. Why Brand Phishing Is Becoming Harder to Spot Brand phishing works because it transfers trust from a familiar organisation to a fraudulent message or website. Across Q2 2026 cases, attackers used urgency, realistic branding, lookalike domains, broken buttons, mismatched links and subtle visual flaws to lower user suspicion and drive faster action. Generative AI is also changing the economics of brand phishing by helping attackers produce more convincing emails and fraudulent websites at scale, making both the volume and sophistication of these attacks likely to grow. With generative AI lowering the barrier to creating convincing fake websites, emails and digital experiences, brand phishing is becoming harder to detect and easier to scale. As trust becomes the primary target, organisations must assume these attacks will continue to grow in both volume and sophistication.
Share
Copy Link
OpenAI's ChatGPT has entered the top 10 most impersonated brands for the first time, accounting for 1.1% of all brand phishing attempts in Q2 2026. Microsoft continues to dominate with 23% of attacks, while generative AI tools enable cybercriminals to create more sophisticated phishing campaigns at scale, targeting users' trust in familiar platforms.
ChatGPT has made its first appearance in the top 10 most impersonated brands, signaling a notable shift in how cybercriminals target trusted platforms. According to Check Point Research's Brand Phishing Ranking for Q2 2026, OpenAI's flagship AI tool now accounts for 1.1% of all tracked brand phishing attempts
1
2
. This marks a clear signal that AI platforms are now firmly on cybercriminals' radar as they become integral to daily workflows for subscriptions, payments and workplace tasks. The appearance of ChatGPT alongside established technology giants reflects how attackers are moving quickly toward the AI platforms people are beginning to rely on every day.
Source: CXOToday
Microsoft continues to remain the most impersonated brand, accounting for 23% of all brand phishing attempts during Q2 2026—nearly double the next closest brand
2
3
. When combined with its LinkedIn subsidiary at 11.6%, Microsoft-related platforms account for 34.2% of all tracked brand impersonations1
. The top five most impersonated brands—Microsoft, LinkedIn, Google at 6.7%, Apple at 5.8%, and Amazon at 5.2%—accounted for more than half of all brand phishing activity tracked this quarter. This concentration underscores how attackers focus on a small group of globally recognized platforms that people use and trust every day, exploiting that trust to steal credentials, payment details and personal information.
Source: TechRadar
One prominent phishing campaign impersonated ChatGPT Plus through a fake subscription payment failure email that copied OpenAI's branding but directed victims to a fraudulent payment page designed to maliciously collect their payment information
1
3
. The campaign led victims to a page designed to steal full credit card details under the guise of resolving a billing issue. Similarly, attackers created fake Microsoft support pages that warned customers they needed to update Office for security fixes, but the download actually installed malware on victim devices. Other documented campaigns included a near-identical PayPal login page with a distorted logo that may indicate the use of AI-generated assets, and fake Apple iCloud login pages using Apple's logo and branding.Generative AI is changing the economics of brand phishing by helping attackers produce more convincing emails and fraudulent websites at scale, making both the volume and sophistication of these attacks likely to grow
2
3
. Omer Dembinsky, Data Research Manager at Check Point Research, noted that "brand phishing is entering a new phase where attackers are not only exploiting trust in household technology names, but also moving quickly toward the AI platforms people are beginning to rely on every day." As generative AI enables criminals to create more credible emails, cloned websites and fake digital experiences at scale, the barrier to launching sophisticated phishing campaigns continues to lower. The irony is that OpenAI's own AI tools, among plenty of others, likely helped attackers write many of these attacks at lightning pace1
.Related Stories
By industry, technology remained the most impersonated sector, followed by social networks and banking, reflecting attackers' continued focus on platforms that hold users' identities, professional relationships and money
2
3
. ChatGPT sees a similar number of attacks to PayPal at 1.3%, WhatsApp at 1.4%, and Facebook at 1.9%1
. Brand phishing works because it transfers trust from a familiar organization to a fraudulent message or website. Across Q2 2026 cases, attackers used urgency, realistic branding, lookalike domains, broken buttons, mismatched links and subtle visual flaws to lower user suspicion and drive faster action.
Source: DT
As AI-driven cyber threats become harder to detect and easier to scale, organizations must shift from reacting after compromise to preventing these threats before users ever engage with them, according to Dembinsky
2
. Security experts warn potential victims to be wary of clicking on unknown URLs and opening unexpected communications. Basic cybersecurity hygiene can prevent many attacks, including protecting accounts with passkeys and secure multi-factor authentication1
. With trust becoming the primary target and generative AI lowering barriers to creating convincing fake websites, emails and digital experiences, organizations must assume these attacks will continue to grow in both volume and sophistication. Watching for subtle indicators like disconnected social media icons, non-functional buttons, and mismatched domains can help users identify fraudulent sites before sharing sensitive information.Summarized by
Navi
[1]
1
Technology

2
Technology

3
Science and Research
