A new name in an old club.
For the first time, ChatGPT has cracked the top 10 most impersonated brands in phishing attacks, according to Check Point’s Q2 2026 Brand Phishing Report.
It’s a notable shift for a list that’s long been dominated by the same handful of household names — Microsoft, LinkedIn, Google, Apple and Amazon — which together account for more than half of all brand phishing attempts tracked this quarter. Microsoft alone made up 22.6% of attempts, nearly double any other brand.
ChatGPT’s share is still small by comparison — about 1.1% of tracked attempts, putting it in the same tier as PayPal (1.3%), WhatsApp (1.4%) and Facebook (1.9%). But the milestone matters because it shows criminals have decided OpenAI’s chatbot is now mainstream enough to be worth faking.
How the scams work
One documented case from June involved a fake ChatGPT Plus payment failure email designed to mimic an official OpenAI billing notice. Clicking through led victims to a fraudulent page built to harvest full credit card numbers.

Check Point says the pattern tracks with how people now use AI tools day to day. “As AI tools move from novelty to daily habit for millions of people managing subscriptions, payments, and work tasks through them, they become just as attractive a target as any bank or tech giant,” the company said.
Other cases this quarter included a cloned Michael Kors storefront that replicated an entire checkout flow, a fake UNIQLO site in a country where the retailer doesn’t operate, and a Microsoft support page pushing a bogus Office security update that actually installed malware. Across nearly all of them, the trigger was urgency.
“Payment failures, security alerts, and required updates all push you to act before you stop to think, which is exactly the point,” Check Point wrote.
Why it’s worth paying attention to
Technology companies were the most targeted sector overall this quarter, followed by social media platforms and banks — the industries that hold the most sensitive pieces of a person’s digital life.
That’s not a coincidence.
Scammers aren’t casting wide nets; they’re narrowing in on the names people trust enough to click without thinking twice.
ChatGPT’s arrival on this list is really a lagging indicator of something that’s already happened: AI chatbots have softly become financial accounts, subscription services, and daily-use tools in their own right, which means they now carry the same fraud risk as a bank login or a streaming subscription.
Expect that risk to compound as more workplaces roll AI tools into billing systems and single sign-on setups, giving scammers more entry points that look routine on the surface. The same AI systems being impersonated are also, ironically, part of what’s making these fakes easier to produce at scale and harder to spot by eye.
Spotting the fake
The tells are usually small: a distorted logo, a login button that doesn’t actually work, a domain that’s almost but not quite right.
Check Point recommends typing a company’s web address directly into a browser rather than clicking email links, hovering over buttons before clicking, and turning on multifactor authentication wherever it’s offered.
If a billing email feels slightly off, verify it through the company’s official site, not through anything in the message itself.
Also read: Jalisco and OmegaLord phishing kits target Microsoft 365 by abusing OAuth device codes and MFA prompts to maintain account access.