ChatGPT Becomes Top 10 Most Impersonated Brand in Phishing Attacks
OpenAI's ChatGPT has entered the top 10 most impersonated brands in phishing attacks, marking a significant shift in threat actor tactics, according to Check Point Research.

OpenAI's popular AI chatbot, ChatGPT, has made its debut in the top 10 most impersonated brands in phishing attacks, a notable first for the rapidly evolving technology. This inclusion, detailed in Check Point Research's Q2 2026 Brand Phishing Report, signifies a growing trend where threat actors are capitalizing on the widespread adoption and user trust in AI tools to lure unsuspecting individuals into malicious schemes.
The report highlights a specific instance observed in June 2026, where attackers distributed a fake "ChatGPT Plus payment failed" email. This sophisticated phishing attempt mimicked OpenAI's official billing notices, directing victims to a fraudulent webpage meticulously designed to harvest full credit card details. The success of such campaigns underscores the increasing sophistication of social engineering tactics that leverage the familiarity and perceived legitimacy of AI platforms.
Check Point Research emphasized that OpenAI's emergence on this list is a strong indicator of where attacker attention is shifting. As AI tools transition from novelties to integral parts of daily routines for millions—managing subscriptions, payments, and work tasks—they naturally become as attractive a target as traditional financial or technology giants. The firm anticipates that AI platforms will continue to climb these rankings in future quarters as their integration into user workflows deepens.
Microsoft retained its position as the most impersonated brand for the second consecutive quarter, accounting for 23% of all phishing attempts. LinkedIn, also owned by Microsoft, followed as the second most targeted, with Google, Apple, and Amazon rounding out the top five. These major technology companies collectively represented over half of all phishing attempts, demonstrating their persistent appeal to cybercriminals seeking to steal login credentials, payment information, or personal data.
Brand phishing, as defined by Check Point, involves scammers impersonating well-known companies through email, fake websites, or both. The observed real-world attacks in Q2 2026 ranged from deceptive payment failure notifications and full replica online stores to fake login pages and malware disguised as software updates. The technology sector was the most targeted industry, followed by social networks and banking, reflecting the critical role these platforms play in users' digital lives.
To combat this escalating threat, Check Point recommends several preventative measures. These include implementing inline phishing message detection to intercept threats before they reach inboxes, utilizing AI-powered detection systems capable of identifying brand impersonation and AI-generated attacks with high accuracy, and consolidating email and workspace protection across various platforms into a unified system to reduce operational complexity. Automating investigation and response processes is also crucial for enabling security teams to address threats more efficiently.
The trend of impersonating popular AI tools like ChatGPT highlights a new frontier in cybercrime. As users become more reliant on these technologies for everyday tasks, the potential for exploitation grows. Security professionals must adapt by enhancing detection capabilities and user education to address these evolving social engineering tactics, ensuring that the convenience of AI does not come at the cost of compromised security.