Microsoft continues to dominate brand impersonation by a wide margin, but the biggest story this quarter is the entry of an AI-native brand. The top five impersonated brands together account for more than half of all brand phishing attempts tracked .
| Rank | Brand | Share of Brand Phishing Attempts |
|---|---|---|
| 1 | Microsoft | 23.0% |
| 2 | 11.6% | |
| 3 | 6.7% | |
| 4 | Apple | 5.8% |
| 5 | Amazon | 5.2% |
| 6–10 | WhatsApp, Facebook, Instagram, Netflix, ChatGPT (ranked ~10th) | ~1–3% each |
Microsoft has held the top spot for multiple consecutive quarters, but LinkedIn’s rise to second place is notable and reflects an increase in professional-credential theft campaigns . ChatGPT’s entry is the headline change: it is the first time an AI platform has cracked the top 10 since Check Point began tracking brand phishing .
The pattern is well-established: as a platform reaches hundreds of millions of users, it becomes a high-value phishing target. The same thing happened with Microsoft, Google, Facebook, and now ChatGPT . “ChatGPT has hundreds of millions of users, and attackers follow the user base,” as multiple cybersecurity analysts have noted .
The most common ChatGPT-themed phishing campaigns do not try to trick users with technical jargon. They exploit a simple, powerful fear: the fear of losing access. Attackers send urgent emails claiming that a ChatGPT Plus payment has failed or that a subscription is about to expire, and they direct victims to lookalike payment portals .
Real-world examples of ChatGPT-targeted phishing include:
The psychological hook is always the same: “You will lose access to GPT-5, your workflows, or your paid plan” .
There are two converging trends at work. First, attackers use generative AI to write more convincing phishing emails with proper branding, logos, and flawless grammar — making it harder for users to spot fakes . Second, attackers are now impersonating AI services themselves to steal credentials and payment data .
More concerning is a vulnerability called ChatGPhish, disclosed in June 2026 by Permiso Security. It demonstrated that any public web page summarized by ChatGPT can inject phishing links, fake security alerts, and QR codes directly into the ChatGPT user interface via indirect prompt injection — without compromising OpenAI’s infrastructure . A user who asks ChatGPT to summarize an attacker-controlled page could see a fraudulent “security alert” or “update your billing” prompt rendered as part of the trusted ChatGPT UI.
Kaspersky reported that ChatGPT-mimicking cyberthreats surged 115% in the first four months of 2025 compared to the prior period . The Q2 2026 ranking formalizes what security firms had been warning: AI services are now firmly on the radar of cybercriminals, and the volume of attacks is growing faster than most users expect.