Threat reportPhishingTL-2026-1665

ChatGPT Enters Top 10 Most-Impersonated Brands as Check Point's Q2 2026 Brand Phishing Report Shows Microsoft, LinkedIn, Google, Apple, Amazon Driving Over Half of All Impersonation Attempts

mediumACTIVE

ChatGPT Enters Top 10 Most-Impersonated Brands as Check (TL-2026-1665), also tracked as ChatGPT Plus Payment Failed phishing campaign, is a medium-severity phishing campaign, first published 2026-07-24. It has no confirmed attribution, affects OpenAI ChatGPT Plus / ChatGPT subscription billing, maps to 16 MITRE ATT&CK techniques (T1027, T1036, T1102), and is covered by 9 detection rules and 18 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
16MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
18Indicators of compromise

Key facts for TL-2026-1665

Threat ID
TL-2026-1665
Also known as
ChatGPT Plus Payment Failed phishing campaign, Check Point Q2 2026 Brand Phishing Report
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, social networks, banking, financialservices, retail, logistics, generalconsumer
Target regions
Global
Detection rules
9
Indicators of compromise
18

How ChatGPT Enters Top 10 Most-Impersonated Brands as Check works

Check Point Research's Q2 2026 Brand Phishing Report shows ChatGPT/OpenAI entering the global top 10 most-impersonated brands for the first time, driven by fake 'ChatGPT Plus payment failed' billing emails that funnel victims to fraudulent Stripe-branded card-harvesting pages. Microsoft (23%), LinkedIn (11.6%), Google (6.7%), Apple (5.8%) and Amazon (5.2%) remain the dominant impersonated identities, together accounting for more than half of all observed brand-phishing volume, with the technology sector the most-targeted industry overall.

Check Point Research published its Q2 2026 Brand Phishing Report on 2026-07-23, tracking which recognizable corporate brands criminals most frequently spoof in credential-harvesting and payment-fraud campaigns. The report's headline finding is the debut of ChatGPT/OpenAI in the global top 10 most-impersonated brands, a first-time appearance that Check Point frames as evidence that AI subscription services have crossed a threshold from novelty to daily financial habit for millions of users — and are consequently now viewed by criminals as targets on par with banks and established technology giants.

The report documents a concrete ChatGPT-themed campaign observed in June 2026: a phishing email spoofing an OpenAI/ChatGPT Plus billing notice, claiming the recipient's subscription payment failed and prompting them to 'update payment details.' Two independently reported variants of this lure exist. One, cataloged by MailGuard, was sent from the lookalike domain imi2001.co.jp with a forged 'Chat GPT' display name, and both call-to-action links in the email redirected to a single fraudulent Stripe-branded payment page hosted on the infrastructure host argentina.alwaysdata.net. That page used VISA-branded loading animations and fabricated 'transaction failed, please retry with a different card' error prompts to coerce victims into re-entering payment data multiple times, maximizing the volume of harvested card numbers, expiry dates, CVC codes, cardholder names, billing addresses, and email addresses. A second reported variant used the Gmail sender address dule9xpro@gmail.com, illustrating that multiple criminal groups or kit variants are independently running the same ChatGPT-billing lure concept rather than a single centralized campaign.

Outside the ChatGPT vector, the broader Q2 2026 report confirms Microsoft as the single most-impersonated brand for the quarter at 23% of all tracked brand-phishing attempts — nearly double the next-closest brand — with LinkedIn (also Microsoft-owned) second at 11.6%, Google third at 6.7%, Apple fourth at 5.8%, and Amazon fifth at 5.2%. Combined, these five brands accounted for more than half of all brand-phishing volume observed in the quarter. Technology was the most-targeted sector overall, followed by social networks and banking. Check Point's report also documented non-AI examples illustrating the same tactics ecosystem: a near-identical fake PayPal login page with a subtly distorted logo (which Check Point suggests may indicate AI-generated phishing asset creation), a fake Microsoft support page pushing an urgent 'Office security update' that instead delivered a disguised executable, and spoofed storefronts impersonating Michael Kors and UNIQLO. Across these campaigns, the report identifies a consistent tactic pattern: manufactured urgency, high-fidelity brand-accurate visual cloning, lookalike/typosquat domains, mismatched or broken action links, and subtle visual flaws intended to lower target suspicion and accelerate victim action before scrutiny.

This is a social-engineering/credential-and-payment-fraud trend threat rather than a software vulnerability: there is no CVE, no exploited software flaw, and no single centralized C2 infrastructure to dismantle. The actionable takeaway for defenders is that AI-assistant billing/subscription notifications are now a viable, actively-exploited phishing lure category that email security controls, security-awareness training, and brand-protection/anti-impersonation monitoring should explicitly account for going forward, alongside the long-established Microsoft/LinkedIn/Google/Apple/Amazon impersonation baseline.

MITRE ATT&CK techniques used in TL-2026-1665

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading

Command and Control

T1102 Web Service; T1105 Ingress Tool Transfer

Collection

T1213 Data from Information Repositories

Credential Access

T1528 Steal Application Access Token; T1557 Adversary-in-the-Middle

Initial Access

T1566 Phishing

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1586 Compromise Accounts; T1587 Develop Capabilities

Reconnaissance

T1589 Gather Victim Identity Information

Impact

T1657 Financial Theft

stealth

T1684.001 Impersonation

Affected products and versions in ChatGPT Enters Top 10 Most-Impersonated Brands as Check

  • OpenAI — ChatGPT Plus / ChatGPT subscription billing
    Vulnerable versions: N/A - brand impersonation, not a software vulnerability
  • Microsoft — Microsoft 365 / Office / Microsoft account identity
    Vulnerable versions: N/A - brand impersonation, not a software vulnerability
  • LinkedIn — LinkedIn account/notification identity
    Vulnerable versions: N/A - brand impersonation, not a software vulnerability
  • PayPal — PayPal login/account identity
    Vulnerable versions: N/A - brand impersonation, not a software vulnerability

Remediation for ChatGPT Enters Top 10 Most-Impersonated Brands as Check

Immediate actions

  • Block/flag inbound mail from the reported lure sender infrastructure: imi2001.co.jp and the free-mail sender dule9xpro@gmail.com when the body impersonates OpenAI/ChatGPT billing
  • Block or sandbox outbound traffic to argentina.alwaysdata.net, which hosted the fraudulent Stripe-branded card-harvesting page
  • Add ChatGPT/OpenAI billing-themed phishing indicators to email security gateway and brand-impersonation detection rulesets alongside existing Microsoft/LinkedIn/Google/Apple/Amazon signatures
  • Alert finance, procurement, and general staff who expense or manage ChatGPT Plus/Team/Enterprise subscriptions that OpenAI and Stripe billing emails will never originate from Gmail or unrelated-country TLD domains

Workarounds

  • Instruct users to manage ChatGPT Plus/Team/Enterprise billing exclusively by navigating directly to chatgpt.com/settings or platform.openai.com rather than clicking email links
  • Enable payment-card alerts/virtual card numbers for AI subscription billing to limit fraud exposure if credentials are harvested

Longer-term hardening

  • Extend brand-protection and typosquat-domain monitoring programs to cover AI-assistant brands (OpenAI/ChatGPT, and by extension Anthropic/Claude, Google Gemini, Microsoft Copilot) given confirmed criminal targeting
  • Incorporate AI-subscription billing lures into recurring security-awareness phishing simulation content
  • Deploy DMARC/DKIM/SPF enforcement and monitor for lookalike domains registered against organizationally-used SaaS/AI vendor names
  • Monitor for AI-generated phishing asset quality improvements (e.g., near-perfect brand clones) that may defeat legacy visual-similarity brand-protection tooling

Weaknesses (CWE) in ChatGPT Enters Top 10 Most-Impersonated Brands as Check

CWE-451, CWE-1021, CWE-290

Timeline of ChatGPT Enters Top 10 Most-Impersonated Brands as Check

  • ChatGPT Plus/OpenAI billing-themed phishing email variants observed in the wild during June 2026, per Check Point Research's Q2 2026 tracking window and independently corroborated by MailGuard's writeup of the imi2001.co.jp / argentina.alwaysdata.net campaign.
  • OpenAI Developer Community members post a scam alert thread flagging fake OpenAI subscription emails requesting payment details, corroborating active in-the-wild targeting of ChatGPT users.
  • Close of Q2 2026 (April-June) brand-phishing data collection window analyzed in Check Point's report.
  • Check Point issues a companion press release corroborating the Microsoft #1 / LinkedIn top-tier rankings for the Q2 2026 reporting period.
  • Check Point Research publishes its Q2 2026 Brand Phishing Report ('The Phishing Paradox') on the Check Point blog, disclosing that ChatGPT/OpenAI entered the global top 10 most-impersonated brands for the first time and detailing the Microsoft/LinkedIn/Google/Apple/Amazon top-5 rankings.
  • RESEARCH phase corroborates the report across seven independent outlets, recovers concrete campaign IOCs (imi2001.co.jp, argentina.alwaysdata.net, dule9xpro@gmail.com) via the MailGuard writeup, and documents the full MITRE ATT&CK phishing kill chain.
  • TL-Intel-Harness HUNT phase ingests the Infosecurity Magazine coverage via RSS and creates threat skeleton TL-2026-1665.
  • Infosecurity Magazine, IT Brief, Security Brief Asia, BizCommunity, and IT Voice publish independent news coverage summarizing and corroborating Check Point's Q2 2026 findings, including the ChatGPT top-10 debut.

Sources cited for ChatGPT Enters Top 10 Most-Impersonated Brands as Check

Detection coverage for TL-2026-1665

As of 2026-07-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1665 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
18 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats