ChatGPT has entered the top 10 most impersonated brands in phishing attacks for the first time, according to a new report from Check Point.
The Q2 2026 Brand Phishing Report shows that OpenAI's chatbot accounted for 1.1% of all brand impersonation phishing attacks globally.
>>> NEC Nijmegen Signs Dusan Tadic on Two-Year Contract
Phishing Attacks Target ChatGPT Users
Cybercriminals used fake emails claiming payment errors in ChatGPT Plus transactions to trick users.
The emails mimicked OpenAI's corporate identity and directed victims to fake payment portals designed to steal credit card details.
Attackers leveraged AI tools to accelerate campaign creation, the report noted.
>>> Cody Gakpo Turns Down Fenerbahce as Liverpool Eyes Barcola
ChatGPT's phishing volume was comparable to other major platforms: PayPal at 1.3%, WhatsApp at 1.4%, and Facebook at 1.9%.
Microsoft retained the top spot with its core brand accounting for 22.6% of attacks, while LinkedIn, a Microsoft subsidiary, added 11.6%.
Technology firms faced the highest overall volume of brand impersonation attacks, followed by social media networks and banking apps.
>>> CPSC Faces Privacy Concerns Over Demand for Patient ER Records
Attackers continue to exploit urgency around recognized brand names to manipulate victims into surrendering credentials or financial information.