ChatGPT joins the phishing target list, signalling a new security challenge for CIOs

For years, Microsoft, Google and Apple have dominated brand phishing campaigns because they are deeply embedded in enterprise and consumer digital ecosystems. That pattern continues, but a new entrant in Check Point Research’s Q2 2026 Brand Phishing Report deserves the attention of every CIO and CISO.

For the first time, ChatGPT has appeared among the world’s top 10 most impersonated brands.

On the surface, the number appears modest. ChatGPT accounted for 1.1% of all brand phishing attempts during the quarter, ranking tenth globally. Microsoft remained the most impersonated brand at 22.6%, followed by LinkedIn (11.6%), Google (6.7%), Apple (5.8%) and Amazon (5.2%).

The significance, however, lies not in ChatGPT’s ranking but in what it represents. Cybercriminals are adapting their playbooks to target the platforms employees increasingly trust and use every day. AI applications have now joined cloud services, collaboration platforms and online banking as attractive vehicles for credential theft, payment fraud and data compromise.

AI has become part of the enterprise attack surface

The inclusion of ChatGPT in the rankings reflects the rapid adoption of generative AI across enterprises. Employees now rely on AI assistants to draft reports, analyse data, write software code, summarize meetings and support everyday business decisions.

As organisations integrate AI into business processes, employees have become accustomed to logging into AI platforms, purchasing subscriptions and sharing business information through conversational interfaces. That familiarity creates an opportunity for attackers to exploit user trust.

Check Point Research observed phishing campaigns that impersonated ChatGPT Plus through fake subscription payment failure emails. Victims were redirected to convincing payment pages designed to capture credit card information.

The tactic is familiar. What has changed is the brand being exploited.

“Brand phishing is entering a new phase where attackers are not only exploiting trust in household technology names, but also moving quickly toward the AI platforms people are beginning to rely on every day,” said Omer Dembinsky, Data Research Manager at Check Point Research. “As generative AI enables criminals to create more credible emails, cloned websites and fake digital experiences at scale, organisations must shift from reacting after compromise to preventing these threats before users ever engage with them.”

Generative AI is raising the quality of phishing attacks

The report also highlights another important shift. Generative AI is improving the quality and scalability of phishing campaigns.

Traditional phishing emails often contained spelling mistakes, inconsistent branding or poor grammar. Those indicators are becoming less reliable as AI tools enable attackers to produce polished emails, realistic websites and convincing customer interactions within minutes.

During the quarter, Check Point documented phishing campaigns that included:

A fake ChatGPT subscription payment page designed to steal financial information.
A counterfeit Michael Kors online store that replicated the complete online shopping experience.
A fraudulent UNIQLO storefront operating in a market where the retailer has no official presence.
A fake Apple iCloud login page using authentic branding.
A Microsoft Office security update page that delivered malware disguised as a software update.
A PayPal login page that appeared to use AI-generated visual assets.

The common thread across these campaigns is that attackers are no longer creating simplistic fake login pages. They are reproducing complete digital experiences that closely resemble legitimate services.

Why enterprise leaders should pay attention

For CIOs, the emergence of AI platforms as phishing targets represents more than another brand appearing in a quarterly ranking.

Enterprise AI deployments are expanding rapidly. Employees routinely upload documents, analyse spreadsheets, review contracts and generate business content using AI assistants. A successful phishing campaign impersonating an AI platform could expose not only user credentials but also confidential corporate information and intellectual property.

Unlike traditional phishing attacks that primarily target passwords or financial information, AI-related phishing campaigns could become gateways to sensitive enterprise data.

As AI adoption grows, organisations should expect threat actors to develop increasingly sophisticated campaigns that exploit employee familiarity with these platforms.

Security awareness programmes need to evolve

The findings also suggest that conventional phishing awareness training requires updating.

Employees have traditionally been trained to identify suspicious emails and verify website URLs. While those practices remain essential, phishing campaigns are increasingly reaching users through search advertisements, messaging platforms, social media, QR codes and browser notifications.

The challenge is no longer limited to recognising fraudulent emails. Employees must also learn to verify the authenticity of digital services and AI platforms before entering credentials, payment details or business information.

Technical controls such as phishing-resistant authentication, browser isolation, DNS filtering and AI-powered threat detection will become increasingly important as attackers leverage AI to automate and personalise phishing campaigns.

Trust remains the primary target

Technology continued to be the most impersonated sector in Q2 2026, followed by social networking and banking. Together, the top five brands accounted for more than half of all phishing activity tracked during the quarter, reinforcing that attackers continue to focus on platforms users trust most.

The appearance of ChatGPT in the top 10 suggests that AI has now reached that level of trust.

For enterprise leaders, the message is clear. As organisations accelerate AI adoption, security strategies must evolve just as quickly. Protecting enterprise AI initiatives will require more than securing the models themselves. It will require defending the growing ecosystem of users, identities and digital experiences that now surround AI.

The next phase of phishing will not simply imitate familiar brands. It will increasingly imitate the AI platforms that enterprises are beginning to depend on every day.

ChatGPTPhishing
Comments (0)
Add Comment