
Brand phishing is taking a new turn, with cybercriminals continuing to exploit familiar names while increasingly turning their attention to AI platforms. The Check Point Research Q2 2026 findings show Microsoft remained the most impersonated brand, accounting for 22.6% of tracked phishing attempts, while ChatGPT entered the top 10 for the first time.
The shift highlights a growing problem for businesses and users. Attackers are not only copying the brands people already trust but are also following changing digital habits. As AI tools become part of everyday work, payments and subscriptions, they are becoming new targets for credential and payment theft.
Microsoft leads as AI enters the top ten
Microsoft remained far ahead of other brands in the Check Point brand phishing report 2026, with 22.6% of all tracked attempts. LinkedIn followed at 11.6%, while Google, Apple and Amazon accounted for 6.7%, 5.8% and 5.2%, respectively.
Together, the five most impersonated brands represented more than half of all brand phishing activity. The pattern suggests that attackers continue to focus on a small group of well-known platforms that users interact with regularly.
However, the arrival of ChatGPT in the top 10 is the more notable development. With 1.1% of brand phishing activity, the ChatGPT phishing target trend shows how quickly cybercriminals are adapting to new technology habits.
AI platforms become new phishing targets
The report points to a wider shift in AI-driven phishing scams. One campaign impersonated ChatGPT Plus using a fake subscription payment failure email that directed victims to a page designed to collect credit card information.
The campaign reflects why AI platforms are becoming attractive targets. Users are increasingly relying on them for daily tasks, subscriptions and workplace activities, creating new opportunities for attackers to exploit trust.
The broader concern is that generative AI can also help criminals create more convincing emails, cloned websites and fake digital experiences at scale. This makes Generative AI cyber threats harder to spot and potentially easier to launch.
Familiar brands still drive the biggest risk
Technology remained the most impersonated sector in Q2 2026, followed by social networks and banking. The focus is not surprising within the report's findings, as these platforms often hold valuable identities, professional relationships, payment information and personal data.
The observed campaigns ranged from fake payment failure notices and replica shopping websites to fraudulent login pages and malware disguised as software updates. Fake stores imitating Michael Kors and UNIQLO, along with fraudulent Apple, PayPal and Microsoft pages, show how attackers use different approaches depending on the information they want to capture.
Read More:
AMD and Anthropic partnership targets gigawatt-scale AI
CrowdStrike and Cerebras partnership aim for faster AI security
Liferay strengthens digital experience platform as AI adoption grows
Sophos Report: Why ransomware is becoming an identity problem
/dqc/media/agency_attachments/2026/08/21/2026-08-21t061716244z-dq-channels-logojpg-2026-08-21-11-47-17.jpeg)
/dqc/media/media_files/2026/09/10/dq-channels-whatsapp-2026-09-10-17-07-48.png)
Follow Us