ChatGPT Enters Check Point's Phishing Brand Ranking
Check Point's Q2 2026 brand-phishing report placed ChatGPT among its 10 most impersonated brands for the first time. The security company documented a June email styled as a "ChatGPT Plus payment failed" notice that directed recipients to a page designed to collect full credit card details. Microsoft remained the leading impersonated brand, accounting for 23% of attempts tracked by Check Point.
Check Point Research's Q2 2026 Brand Phishing Ranking placed ChatGPT among its 10 most impersonated brands for the first time. The report, published July 24, documented a June phishing email styled as a "ChatGPT Plus payment failed" billing notice that redirected recipients to a page designed to collect full credit card details.
According to Check Point, Microsoft remained the most impersonated brand in the quarter, appearing in 23% of brand-phishing attempts it tracked. LinkedIn ranked second at 11.6%, followed by Google at 6.7%, Apple at 5.8%, and Amazon at 5.2%, according to the company's published ranking. Check Point reported that those five brands together represented more than half of the tracked activity.
A payment-themed lure
Infosecurity Magazine reported that the malicious ChatGPT email was made to resemble an OpenAI billing communication. Its landing page was built to capture payment-card information, rather than to process a legitimate subscription payment.
Check Point defines brand phishing as impersonating a trusted company by email, fake website, or both, to obtain credentials, payment data, or personal information. Its Q2 examples also included replica online stores, fake login pages, and malware presented as software updates.
Check Point characterized ChatGPT's arrival in the ranking as evidence that AI services have drawn attacker attention alongside established technology, social-networking, and banking brands. Cybersecurity Asia, reporting the same findings, noted that technology was the most impersonated sector in the quarter, followed by social networks and banking.
What the ranking measures
The ranking is a measure of the brand names used in phishing attempts tracked by Check Point, not a measure of compromise rates, successful fraud, or weaknesses in the underlying services. The published material does not state ChatGPT's exact position or percentage within the top 10.
That distinction matters for security teams. Brand impersonation exploits recognition and routine: a recipient who regularly manages a subscription, receives billing notices, or uses an AI service for work may treat a payment-failure message as ordinary account administration. Similar patterns across consumer and enterprise SaaS show why mail controls need to assess sender domains, destination URLs, and credential or payment-data collection behavior, rather than relying only on the apparent brand in a message.
Practical indicators in the reported campaigns
Check Point identified several recurring indicators across the quarter's phishing examples:
- •Distorted or inconsistent logos and branding
- •Nonfunctional buttons or mismatched social-media links
- •Urgent wording intended to prompt rapid action
- •Fake login or payment pages reached through an email link
For AI and data teams, the report adds a security consideration around access to paid AI services. Where employees use browser-based subscriptions, phishing-resistant authentication, approved procurement paths, and user reporting workflows can reduce reliance on a recipient's ability to distinguish a legitimate billing request from a visually convincing imitation. These are common controls for comparable SaaS impersonation risks; Check Point's report does not evaluate individual organizations' defenses or the effectiveness of any specific mitigation.
Key Points
- 1Check Point tracked ChatGPT among its 10 most impersonated brands after observing a payment-failure lure targeting credit card data.
- 2Microsoft represented 23% of tracked Q2 brand-phishing attempts, showing attacker concentration around a small set of widely recognized platforms.
- 3Comparable SaaS phishing campaigns make URL verification, phishing-resistant authentication, and approved payment workflows relevant controls for AI-service users.
Scoring Rationale
The report documents a new phishing lure using a major AI product's brand and a payment-card theft flow, making it relevant to teams managing AI-service access. It is a threat-intelligence finding rather than a reported compromise of ChatGPT or an underlying product vulnerability.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems


