OpenAI's ChatGPT has entered the top 10 list of most impersonated brands in phishing attacks, according to new research from Check Point. The AI chatbot now accounts for 1.1% of all tracked brand impersonations, placing it alongside established targets such as Microsoft, Google and Apple.

What You Need to Know

Cybercriminals are increasingly using fake brand pages and emails to steal login credentials and payment data. Though ChatGPT accounts for only a small fraction of attacks, its rapid rise reflects the growing value of AI-related accounts. Microsoft and its subsidiary LinkedIn together account for more than a third of all impersonation attempts. Basic security measures such as multi-factor authentication can prevent many of these attacks.

Phishing Attack Volume and Brand Targeting

Check Point's Q2 2026 Brand Phishing Report tracked impersonation attempts across major companies. Microsoft and LinkedIn combined represent 34.2% of all tracked attacks, far outpacing other brands. Google, Apple and Facebook also appear in the top 10, with PayPal, WhatsApp and now ChatGPT rounding out the list.

Though ChatGPT accounts for only 1.1% of impersonations, its entry into the top 10 marks a significant shift. The number of attacks targeting OpenAI's brand is comparable to those targeting PayPal (1.3%) and WhatsApp (1.4%). Security experts attribute this rise to the popularity of paid services such as ChatGPT Plus, which attackers can exploit to collect payment credentials.

Common Attack Vectors and Examples

Attackers employ a variety of methods to deceive users. One notable campaign from the second quarter of 2026 involved fake ChatGPT Plus payment failure emails. These messages copied OpenAI's branding and directed victims to a fraudulent payment page designed to harvest credit card details.

  • Fake payment alerts: Victims receive emails stating their ChatGPT Plus subscription payment failed, with a link to a phishing site.
  • Support page scams: Microsoft-themed attacks warn users to update Office for security fixes, but the download installs malware.
  • Urgency tactics: All campaigns emphasize limited time or account suspension to pressure victims into clicking without verification.

Tech companies remain the most targeted sector overall, followed by social media platforms and banking apps. The attack vector relies on exploiting human behavior rather than technical vulnerabilities, making user education a critical defense.

Why This Matters

The entry of ChatGPT into the most-impersonated list signals a broader shift in cybercriminal strategy. As AI tools become more embedded in daily work and personal life, the value of account credentials rises. Attackers can gain access to sensitive data, including email threads, payment information and connected services. For businesses that rely on ChatGPT Plus for enterprise workflows, a single compromised account could lead to data breaches or financial loss. The growing sophistication of phishing lures, increasingly generated with the help of AI tools themselves, makes detection harder for average users. Organizations must invest in employee training and adopt passkeys or hardware-based multi-factor authentication to reduce risk.

Protecting Yourself Against Brand Impersonation

Cybersecurity hygiene remains the most effective defense. Security experts recommend verifying URLs before clicking, avoiding unsolicited communications and using unique passwords for each account. Multi-factor authentication, especially with a passkey or authenticator app, can block most unauthorized access attempts even if credentials are stolen. For ChatGPT users, enabling two-factor authentication on the OpenAI account adds an extra layer of protection. Staying informed about the latest impersonation trends helps users recognize suspicious messages before they fall victim.