ChatGPT (OpenAI) entered the top 10 most impersonated brands in phishing attacks for the first time in Q2 2026, accounting for 1.1% of all tracked brand phishing attempts.

Create a landscape editorial hero image for this Studio Global article: Search & fact-check with cited sources for Which brands are most impersonated in phishing attacks, and what does ChatGPT's first appearance. Article summary: Here is the full picture, based on Check Point Research's Q2 2026 Brand Phishing Report (published July 23–24, 2026) and corroborating sources.. Topic tags: general, general web, user generated, documentation. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail lay
For the first time in its history, OpenAI’s ChatGPT has joined the list of the world’s most impersonated brands in phishing attacks. According to Check Point Research’s Q2 2026 Brand Phishing Report — published July 23–24, 2026 — ChatGPT accounted for 1.1% of all brand phishing attempts globally during the quarter, making it the only AI service in the top 10. The report signals a clear shift: cybercriminals are now treating AI platforms as prime phishing real estate, and they are deploying targeted, subscription-anxiety scams at scale .
Microsoft continues to dominate brand impersonation by a wide margin, but the biggest story this quarter is the entry of an AI-native brand. The top five impersonated brands together account for more than half of all brand phishing attempts tracked .
| Rank | Brand | Share of Brand Phishing Attempts |
|---|---|---|
| 1 | Microsoft | 23.0% |
| 2 | 11.6% | |
| 3 | 6.7% | |
| 4 | Apple | 5.8% |
| 5 | Amazon | 5.2% |
| 6–10 | WhatsApp, Facebook, Instagram, Netflix, ChatGPT (ranked ~10th) | ~1–3% each |
Microsoft has held the top spot for multiple consecutive quarters, but LinkedIn’s rise to second place is notable and reflects an increase in professional-credential theft campaigns . ChatGPT’s entry is the headline change: it is the first time an AI platform has cracked the top 10 since Check Point began tracking brand phishing
.
The pattern is well-established: as a platform reaches hundreds of millions of users, it becomes a high-value phishing target. The same thing happened with Microsoft, Google, Facebook, and now ChatGPT . “ChatGPT has hundreds of millions of users, and attackers follow the user base,” as multiple cybersecurity analysts have noted
.
The most common ChatGPT-themed phishing campaigns do not try to trick users with technical jargon. They exploit a simple, powerful fear: the fear of losing access. Attackers send urgent emails claiming that a ChatGPT Plus payment has failed or that a subscription is about to expire, and they direct victims to lookalike payment portals .
Real-world examples of ChatGPT-targeted phishing include:
The psychological hook is always the same: “You will lose access to GPT-5, your workflows, or your paid plan” .
There are two converging trends at work. First, attackers use generative AI to write more convincing phishing emails with proper branding, logos, and flawless grammar — making it harder for users to spot fakes . Second, attackers are now impersonating AI services themselves to steal credentials and payment data
.
More concerning is a vulnerability called ChatGPhish, disclosed in June 2026 by Permiso Security. It demonstrated that any public web page summarized by ChatGPT can inject phishing links, fake security alerts, and QR codes directly into the ChatGPT user interface via indirect prompt injection — without compromising OpenAI’s infrastructure . A user who asks ChatGPT to summarize an attacker-controlled page could see a fraudulent “security alert” or “update your billing” prompt rendered as part of the trusted ChatGPT UI.
Kaspersky reported that ChatGPT-mimicking cyberthreats surged 115% in the first four months of 2025 compared to the prior period . The Q2 2026 ranking formalizes what security firms had been warning: AI services are now firmly on the radar of cybercriminals, and the volume of attacks is growing faster than most users expect.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
ChatGPT (OpenAI) entered the top 10 most impersonated brands in phishing attacks for the first time in Q2 2026, accounting for 1.1% of all tracked brand phishing attempts.