Microsoft Tops Q2 Brand Phishing as ChatGPT Enters Top 10

Check Point Research, the threat intelligence arm of Check Point Software Technologies, has released its Brand Phishing Ranking for Q2 2026, finding that Microsoft remained the most impersonated brand at 22.6 per cent of all brand phishing attempts, nearly double the next closest brand, while OpenAI’s ChatGPT made its first appearance among the top ten most imitated brands.

LinkedIn ranked second at 11.6 per cent, followed by Google at 6.7 per cent, Apple at 5.8 per cent and Amazon at 5.2 per cent. Together, the top five impersonated brands accounted for more than half of all brand phishing activity tracked during the quarter, underscoring how attackers are concentrating on a small group of globally recognised platforms that people use and trust every day.

AI platforms enter cybercriminals’ radar

A notable shift this quarter was the first appearance of ChatGPT among the top ten most impersonated brands, at 1.1 per cent. Check Point said this marks a clear signal that AI tools are now firmly on cybercriminals’ radar, as AI platforms become part of daily workflows for subscriptions, payments and workplace tasks, making them attractive targets in the same way as established technology and financial brands.

By industry, technology remained the most impersonated sector, followed by social networks and banking, reflecting attackers’ continued focus on platforms that hold users’ identities, professional relationships and money.

“Brand phishing is entering a new phase where attackers are not only exploiting trust in household technology names, but also moving quickly toward the AI platforms people are beginning to rely on every day. As generative AI enables criminals to create more credible emails, cloned websites and fake digital experiences at scale, organisations must shift from reacting after compromise to preventing these threats before users ever engage with them,” said Omer Dembinsky, Data Research Manager at Check Point Research.

Real-world campaigns show growing sophistication

The report documented a wide range of techniques observed in Q2 2026, from fake payment failure notices to replica online stores, fraudulent login pages and malware disguised as software updates. One campaign impersonated a ChatGPT Plus subscription payment failure to steal full credit card details, while another used a lookalike Michael Kors online store that replicated the entire shopping journey to capture payment information.

Other cases included a fake regional storefront for a brand that does not officially operate in that market, a near-identical PayPal login page with a distorted logo that may indicate AI-generated assets, and a fake Microsoft support page pushing an urgent Office security update that instead delivered a disguised executable file.

  • Microsoft — 22.6%
  • LinkedIn — 11.6%
  • Google — 6.7%
  • Apple — 5.8%
  • Amazon — 5.2%
  • Adobe — 3.8%
  • Facebook — 1.9%
  • WhatsApp — 1.4%
  • PayPal — 1.3%
  • ChatGPT — 1.1%

Check Point said generative AI is changing the economics of brand phishing by helping attackers produce more convincing emails and fraudulent websites at scale, meaning both the volume and sophistication of these attacks are likely to keep growing.

Author


Discover more from techcoffeehouse.com

Subscribe to get the latest posts sent to your email.

Use promo code “TCH15” to get 15% off on checkout.

Share your thoughts

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading