Threat reportPhishingTL-2026-1665
ChatGPT Enters Top 10 Most-Impersonated Brands as Check Point's Q2 2026 Brand Phishing Report Shows Microsoft, LinkedIn, Google, Apple, Amazon Driving Over Half of All Impersonation Attempts
ChatGPT Enters Top 10 Most-Impersonated Brands as Check (TL-2026-1665), also tracked as ChatGPT Plus Payment Failed phishing campaign, is a medium-severity phishing campaign, first published 2026-07-24. It has no confirmed attribution, affects OpenAI ChatGPT Plus / ChatGPT subscription billing, maps to 16 MITRE ATT&CK techniques (T1027, T1036, T1102), and is covered by 9 detection rules and 18 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 18Indicators of compromise
Key facts for TL-2026-1665
- Threat ID
- TL-2026-1665
- Also known as
- ChatGPT Plus Payment Failed phishing campaign, Check Point Q2 2026 Brand Phishing Report
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, social networks, banking, financialservices, retail, logistics, generalconsumer
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 18
How ChatGPT Enters Top 10 Most-Impersonated Brands as Check works
Check Point Research's Q2 2026 Brand Phishing Report shows ChatGPT/OpenAI entering the global top 10 most-impersonated brands for the first time, driven by fake 'ChatGPT Plus payment failed' billing emails that funnel victims to fraudulent Stripe-branded card-harvesting pages. Microsoft (23%), LinkedIn (11.6%), Google (6.7%), Apple (5.8%) and Amazon (5.2%) remain the dominant impersonated identities, together accounting for more than half of all observed brand-phishing volume, with the technology sector the most-targeted industry overall.
Check Point Research published its Q2 2026 Brand Phishing Report on 2026-07-23, tracking which recognizable corporate brands criminals most frequently spoof in credential-harvesting and payment-fraud campaigns. The report's headline finding is the debut of ChatGPT/OpenAI in the global top 10 most-impersonated brands, a first-time appearance that Check Point frames as evidence that AI subscription services have crossed a threshold from novelty to daily financial habit for millions of users — and are consequently now viewed by criminals as targets on par with banks and established technology giants.
The report documents a concrete ChatGPT-themed campaign observed in June 2026: a phishing email spoofing an OpenAI/ChatGPT Plus billing notice, claiming the recipient's subscription payment failed and prompting them to 'update payment details.' Two independently reported variants of this lure exist. One, cataloged by MailGuard, was sent from the lookalike domain imi2001.co.jp with a forged 'Chat GPT' display name, and both call-to-action links in the email redirected to a single fraudulent Stripe-branded payment page hosted on the infrastructure host argentina.alwaysdata.net. That page used VISA-branded loading animations and fabricated 'transaction failed, please retry with a different card' error prompts to coerce victims into re-entering payment data multiple times, maximizing the volume of harvested card numbers, expiry dates, CVC codes, cardholder names, billing addresses, and email addresses. A second reported variant used the Gmail sender address dule9xpro@gmail.com, illustrating that multiple criminal groups or kit variants are independently running the same ChatGPT-billing lure concept rather than a single centralized campaign.
Outside the ChatGPT vector, the broader Q2 2026 report confirms Microsoft as the single most-impersonated brand for the quarter at 23% of all tracked brand-phishing attempts — nearly double the next-closest brand — with LinkedIn (also Microsoft-owned) second at 11.6%, Google third at 6.7%, Apple fourth at 5.8%, and Amazon fifth at 5.2%. Combined, these five brands accounted for more than half of all brand-phishing volume observed in the quarter. Technology was the most-targeted sector overall, followed by social networks and banking. Check Point's report also documented non-AI examples illustrating the same tactics ecosystem: a near-identical fake PayPal login page with a subtly distorted logo (which Check Point suggests may indicate AI-generated phishing asset creation), a fake Microsoft support page pushing an urgent 'Office security update' that instead delivered a disguised executable, and spoofed storefronts impersonating Michael Kors and UNIQLO. Across these campaigns, the report identifies a consistent tactic pattern: manufactured urgency, high-fidelity brand-accurate visual cloning, lookalike/typosquat domains, mismatched or broken action links, and subtle visual flaws intended to lower target suspicion and accelerate victim action before scrutiny.
This is a social-engineering/credential-and-payment-fraud trend threat rather than a software vulnerability: there is no CVE, no exploited software flaw, and no single centralized C2 infrastructure to dismantle. The actionable takeaway for defenders is that AI-assistant billing/subscription notifications are now a viable, actively-exploited phishing lure category that email security controls, security-awareness training, and brand-protection/anti-impersonation monitoring should explicitly account for going forward, alongside the long-established Microsoft/LinkedIn/Google/Apple/Amazon impersonation baseline.
MITRE ATT&CK techniques used in TL-2026-1665
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
Command and Control
T1102 Web Service; T1105 Ingress Tool Transfer
Collection
T1213 Data from Information Repositories
Credential Access
T1528 Steal Application Access Token; T1557 Adversary-in-the-Middle
Initial Access
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1586 Compromise Accounts; T1587 Develop Capabilities
Reconnaissance
T1589 Gather Victim Identity Information
Impact
stealth
Affected products and versions in ChatGPT Enters Top 10 Most-Impersonated Brands as Check
- OpenAI — ChatGPT Plus / ChatGPT subscription billing
Vulnerable versions: N/A - brand impersonation, not a software vulnerability - Microsoft — Microsoft 365 / Office / Microsoft account identity
Vulnerable versions: N/A - brand impersonation, not a software vulnerability - LinkedIn — LinkedIn account/notification identity
Vulnerable versions: N/A - brand impersonation, not a software vulnerability - PayPal — PayPal login/account identity
Vulnerable versions: N/A - brand impersonation, not a software vulnerability
Remediation for ChatGPT Enters Top 10 Most-Impersonated Brands as Check
Immediate actions
- Block/flag inbound mail from the reported lure sender infrastructure: imi2001.co.jp and the free-mail sender dule9xpro@gmail.com when the body impersonates OpenAI/ChatGPT billing
- Block or sandbox outbound traffic to argentina.alwaysdata.net, which hosted the fraudulent Stripe-branded card-harvesting page
- Add ChatGPT/OpenAI billing-themed phishing indicators to email security gateway and brand-impersonation detection rulesets alongside existing Microsoft/LinkedIn/Google/Apple/Amazon signatures
- Alert finance, procurement, and general staff who expense or manage ChatGPT Plus/Team/Enterprise subscriptions that OpenAI and Stripe billing emails will never originate from Gmail or unrelated-country TLD domains
Workarounds
- Instruct users to manage ChatGPT Plus/Team/Enterprise billing exclusively by navigating directly to chatgpt.com/settings or platform.openai.com rather than clicking email links
- Enable payment-card alerts/virtual card numbers for AI subscription billing to limit fraud exposure if credentials are harvested
Longer-term hardening
- Extend brand-protection and typosquat-domain monitoring programs to cover AI-assistant brands (OpenAI/ChatGPT, and by extension Anthropic/Claude, Google Gemini, Microsoft Copilot) given confirmed criminal targeting
- Incorporate AI-subscription billing lures into recurring security-awareness phishing simulation content
- Deploy DMARC/DKIM/SPF enforcement and monitor for lookalike domains registered against organizationally-used SaaS/AI vendor names
- Monitor for AI-generated phishing asset quality improvements (e.g., near-perfect brand clones) that may defeat legacy visual-similarity brand-protection tooling
Weaknesses (CWE) in ChatGPT Enters Top 10 Most-Impersonated Brands as Check
Timeline of ChatGPT Enters Top 10 Most-Impersonated Brands as Check
- ChatGPT Plus/OpenAI billing-themed phishing email variants observed in the wild during June 2026, per Check Point Research's Q2 2026 tracking window and independently corroborated by MailGuard's writeup of the imi2001.co.jp / argentina.alwaysdata.net campaign.
- OpenAI Developer Community members post a scam alert thread flagging fake OpenAI subscription emails requesting payment details, corroborating active in-the-wild targeting of ChatGPT users.
- Close of Q2 2026 (April-June) brand-phishing data collection window analyzed in Check Point's report.
- Check Point issues a companion press release corroborating the Microsoft #1 / LinkedIn top-tier rankings for the Q2 2026 reporting period.
- Check Point Research publishes its Q2 2026 Brand Phishing Report ('The Phishing Paradox') on the Check Point blog, disclosing that ChatGPT/OpenAI entered the global top 10 most-impersonated brands for the first time and detailing the Microsoft/LinkedIn/Google/Apple/Amazon top-5 rankings.
- RESEARCH phase corroborates the report across seven independent outlets, recovers concrete campaign IOCs (imi2001.co.jp, argentina.alwaysdata.net, dule9xpro@gmail.com) via the MailGuard writeup, and documents the full MITRE ATT&CK phishing kill chain.
- TL-Intel-Harness HUNT phase ingests the Infosecurity Magazine coverage via RSS and creates threat skeleton TL-2026-1665.
- Infosecurity Magazine, IT Brief, Security Brief Asia, BizCommunity, and IT Voice publish independent news coverage summarizing and corroborating Check Point's Q2 2026 findings, including the ChatGPT top-10 debut.
Sources cited for ChatGPT Enters Top 10 Most-Impersonated Brands as Check
- ChatGPT most impersonated brands - Infosecurity Magazine
- The Phishing Paradox: The World's Most Trusted Brands Are Cyber Criminals' Entry Point of Choice - Check Point Blog
- Microsoft tops brand phishing list in Q2 2026 report - IT Brief
- Microsoft tops brand phishing list in Q2 2026 report - Security Brief Asia
- ChatGPT enters global ranking of most impersonated brands - BizCommunity
- Check Point Research: Microsoft Leads Q2 2026 Brand Phishing as ChatGPT Emerges as a New Phishing Target - IT Voice
- ChatGPT 'Update your payment details' phishing email leads to fake Stripe payment page - MailGuard
- Scam Alert: Fake OpenAI Subscription Email Requesting Payment Details - OpenAI Developer Community
- LinkedIn Still Number One Brand to be Faked in Phishing Attempts while Microsoft Surges up the Rankings to Number Two Spot in Q2 Report - Check Point Press Release
- Scammers Most Likely to Impersonate DHL, Warns New Brand Phishing Report - Check Point Software
Detection coverage for TL-2026-1665
As of 2026-07-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1665 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.