Skip to content
ChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks, Says Check Point

ChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks, Says Check Point

Infosecurity-Magazine • July 24, 2026

Open AI’s ChatGPT entered the top 10 of the most impersonated brands in phishing attacks for the first time in the second quarter of 2026, according to a Check Point study.

This included a fake "ChatGPT Plus payment failed" email the cybersecurity company observed in June. The malicious email was dressed up to look exactly like an OpenAI billing notice and led victims to a page built purely to steal full credit card details.

The inclusion of OpenAI’s top customer-focused tool is “a strong signal of where attacker attention is heading ,” said Check Point.

“As AI tools move from novelty to daily habit for millions of people managing subscriptions, payments, and work tasks through them, they become just as attractive a target as any bank or tech giant. Expect AI platforms to keep climbing this list in future quarters.”

As detailed in Check Point’s Q2 Brand Phishing Report, Microsoft remains the top impersonated brand, , as it did in the quarter. It accounts for 23% of all phishing attempts, nearly double the of , the second-most targeted brand – also owned by Microsoft.

Google, Apple and Amazon also made the top five most impersonated brands, which accounted for over half of all phishing attempts.

Brand phishing is described by Check Point as an operation where a scammer impersonates a trusted, well-known company, through email, a fake website or both, in order to steal login credentials, payment details or personal information.

Real world cases this quarter ranged from fake payment failure emails to full replica online stores, fake login pages and malware disguised as software updates.

As the top five most impersonated brands in Q2 2026 suggests, technology was the most targeted industry overall, followed by social networks and banking.

Other real cases in the report included a cloned Michael Kors store that replicates the entire checkout, a fake UNIQLO storefront in a country where it doesn't even operate and a dodgy PayPal login page with a warped logo that looks AI-generated.

In a blog published on July 23, Check Point provided recommendations to mitigate the threat of brand phishing. These include:

Image credit: Celia Ong / CKA / Shutterstock.com

Extracted Entities

Attack Types (1)

MITRE ATT&CK (1)