ChatGPT phishing scams have suddenly become a hot topic since IT security firm Check Point Software published its latest Brand Phishing Report for Q2 2026. The report shows that Microsoft remains the most imitated brand in phishing attacks, accounting for nearly 23 percent of all identified attempts. At the same time, ChatGPT enters the top ten list for the first time, marking a clear shift.
Cybercriminals continue to exploit what people already trust. Well-known brands are used as digital disguises to trick users into giving up login credentials, payment information, and other sensitive data. During the quarter, Microsoft accounted for 22.6 percent of all recorded phishing campaigns, followed by LinkedIn at 11.6 percent, Google at 6.7 percent, Apple at 5.8 percent, and Amazon at 5.2 percent. Together, these five brands accounted for more than half of all brand-based phishing activity recorded by Check Point Research during the period.
The biggest news in the report is that ChatGPT is now among the ten most imitated brands for the first time. In one of the analyzed attacks, fake emails were sent that appeared to come from ChatGPT Plus and claimed that a payment had failed. The recipient was then directed to a fake payment page, designed to collect credit card details. It is a reminder of how quickly AI services have become a natural part of both work and everyday life. As a result, they have also become a new front line for fraudsters.
The report also shows that the technology sector remains the most vulnerable industry, closely followed by social media and finance. Examples this quarter include fake online stores, copies of Apple and PayPal login pages, and a fake Microsoft page that lured with a purported security update, but instead downloaded malware.

– Brand-based phishing is entering a new phase, says Omer Dembinsky, Data Research Manager at Check Point Research. Attackers are no longer just exploiting the trust in well-known technology companies, but are also targeting AI platforms that people have quickly started using in their everyday lives. At the same time, generative AI is enabling the creation of significantly more convincing emails, copied websites, and fake digital experiences at scale. Organizations need to shift their focus from reacting after a breach to stopping threats before users even have a chance to interact with them.
The most imitated brands in the second quarter of 2026 were:
- Microsoft – 22.6 percent
- LinkedIn – 11.6 percent
- Google – 6.7 percent
- Apple – 5.8 percent
- Amazon – 5.2 percent
- Adobe – 3.8 percent
- Facebook – 1.9 percent
- WhatsApp – 1.4 percent
- PayPal – 1.3 percent
- ChatGPT – 1.1 percent
The report is based on data from Check Point Research and the company's global threat platform ThreatCloud.
You can read the full report at Check Point blog.
How to protect yourself against ChatGPT phishing scam
The fact that ChatGPT now appears among the most imitated brands shows how quickly attackers adapt to new habits. As more and more people use AI services on a daily basis, something we previously wrote about in the article when AI writes the code, security must be rethought, a ChatGPT phishing scam becomes significantly more credible to the recipient, as emails about accounts, payments, and subscriptions feel plausible. The scammers exploit this sense of trust to get users to act quickly and without thinking.
To reduce your risk, always check the sender address carefully, avoid clicking on links directly in emails, and instead log in via the official website. Be especially vigilant about messages that create time pressure, such as claims that a payment has failed or that an account is about to be suspended. Enable two-factor authentication where possible, and regularly check which devices and sessions have access to your accounts.
For organizations, protecting against ChatGPT phishing scams is about more than technology. Regular employee training, clear procedures for reporting suspicious emails, and proactive monitoring of newly registered domains that mimic well-known brands are crucial. By combining an aware workforce with modern security tools, threats can be stopped before users even have a chance to interact with them.








