A new name in an old club.
For the first time, ChatGPT has cracked the top 10 most impersonated brands in phishing attacks, according to Check Pointâs Q2 2026 Brand Phishing Report.
Itâs a notable shift for a list thatâs long been dominated by the same handful of household names â Microsoft, LinkedIn, Google, Apple and Amazon â which together account for more than half of all brand phishing attempts tracked this quarter. Microsoft alone made up 22.6% of attempts, nearly double any other brand.
ChatGPTâs share is still small by comparison â about 1.1% of tracked attempts, putting it in the same tier as PayPal (1.3%), WhatsApp (1.4%) and Facebook (1.9%). But the milestone matters because it shows criminals have decided OpenAIâs chatbot is now mainstream enough to be worth faking.
How the scams work
One documented case from June involved a fake ChatGPT Plus payment failure email designed to mimic an official OpenAI billing notice. Clicking through led victims to a fraudulent page built to harvest full credit card numbers.
Check Point says the pattern tracks with how people now use AI tools day to day. âAs AI tools move from novelty to daily habit for millions of people managing subscriptions, payments, and work tasks through them, they become just as attractive a target as any bank or tech giant,â the company said.
Other cases this quarter included a cloned Michael Kors storefront that replicated an entire checkout flow, a fake UNIQLO site in a country where the retailer doesnât operate, and a Microsoft support page pushing a bogus Office security update that actually installed malware. Across nearly all of them, the trigger was urgency.
âPayment failures, security alerts, and required updates all push you to act before you stop to think, which is exactly the point,â Check Point wrote.
Why itâs worth paying attention to
Technology companies were the most targeted sector overall this quarter, followed by social media platforms and banks â the industries that hold the most sensitive pieces of a personâs digital life.
Thatâs not a coincidence.
Scammers arenât casting wide nets; theyâre narrowing in on the names people trust enough to click without thinking twice.
ChatGPTâs arrival on this list is really a lagging indicator of something thatâs already happened:Â AI chatbots have softly become financial accounts, subscription services, and daily-use tools in their own right, which means they now carry the same fraud risk as a bank login or a streaming subscription.
Expect that risk to compound as more workplaces roll AI tools into billing systems and single sign-on setups, giving scammers more entry points that look routine on the surface. The same AI systems being impersonated are also, ironically, part of whatâs making these fakes easier to produce at scale and harder to spot by eye.
Spotting the fake
The tells are usually small: a distorted logo, a login button that doesnât actually work, a domain thatâs almost but not quite right.
Check Point recommends typing a companyâs web address directly into a browser rather than clicking email links, hovering over buttons before clicking, and turning on multifactor authentication wherever itâs offered.
If a billing email feels slightly off, verify it through the companyâs official site, not through anything in the message itself.
Also read: Jalisco and OmegaLord phishing kits target Microsoft 365 by abusing OAuth device codes and MFA prompts to maintain account access.
Read the full article here