# ChatGPT Enters Top 10 Most-Impersonated Brands as Check Point's Q2 2026 Brand Phishing Report Shows Microsoft, LinkedIn, Google, Apple, Amazon Driving Over Half of All Impersonation Attempts

> Check Point Research's Q2 2026 Brand Phishing Report shows ChatGPT/OpenAI entering the global top 10 most-impersonated brands for the first time, driven by fake 'ChatGPT Plus payment failed' billing emails that funnel victims to fraudulent Stripe-branded card-harvesting pages. Microsoft (23%), LinkedIn (11.6%), Google (6.7%), Apple (5.8%) and Amazon (5.2%) remain the dominant impersonated identities, together accounting for more than half of all observed brand-phishing volume, with the technology sector the most-targeted industry overall.

- **Published:** 2026-07-24T00:00:00Z
- **Last reviewed:** 2026-07-24T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1665
- **ID:** TL-2026-1665
- **Severity:** MEDIUM
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Check Point Research published its Q2 2026 Brand Phishing Report on 2026-07-23, tracking which recognizable corporate brands criminals most frequently spoof in credential-harvesting and payment-fraud campaigns. The report's headline finding is the debut of ChatGPT/OpenAI in the global top 10 most-impersonated brands, a first-time appearance that Check Point frames as evidence that AI subscription services have crossed a threshold from novelty to daily financial habit for millions of users — and are consequently now viewed by criminals as targets on par with banks and established technology giants.

The report documents a concrete ChatGPT-themed campaign observed in June 2026: a phishing email spoofing an OpenAI/ChatGPT Plus billing notice, claiming the recipient's subscription payment failed and prompting them to 'update payment details.' Two independently reported variants of this lure exist. One, cataloged by MailGuard, was sent from the lookalike domain imi2001.co.jp with a forged 'Chat GPT' display name, and both call-to-action links in the email redirected to a single fraudulent Stripe-branded payment page hosted on the infrastructure host argentina.alwaysdata.net. That page used VISA-branded loading animations and fabricated 'transaction failed, please retry with a different card' error prompts to coerce victims into re-entering payment data multiple times, maximizing the volume of harvested card numbers, expiry dates, CVC codes, cardholder names, billing addresses, and email addresses. A second reported variant used the Gmail sender address dule9xpro@gmail.com, illustrating that multiple criminal groups or kit variants are independently running the same ChatGPT-billing lure concept rather than a single centralized campaign.

Outside the ChatGPT vector, the broader Q2 2026 report confirms Microsoft as the single most-impersonated brand for the quarter at 23% of all tracked brand-phishing attempts — nearly double the next-closest brand — with LinkedIn (also Microsoft-owned) second at 11.6%, Google third at 6.7%, Apple fourth at 5.8%, and Amazon fifth at 5.2%. Combined, these five brands accounted for more than half of all brand-phishing volume observed in the quarter. Technology was the most-targeted sector overall, followed by social networks and banking. Check Point's report also documented non-AI examples illustrating the same tactics ecosystem: a near-identical fake PayPal login page with a subtly distorted logo (which Check Point suggests may indicate AI-generated phishing asset creation), a fake Microsoft support page pushing an urgent 'Office security update' that instead delivered a disguised executable, and spoofed storefronts impersonating Michael Kors and UNIQLO. Across these campaigns, the report identifies a consistent tactic pattern: manufactured urgency, high-fidelity brand-accurate visual cloning, lookalike/typosquat domains, mismatched or broken action links, and subtle visual flaws intended to lower target suspicion and accelerate victim action before scrutiny.

This is a social-engineering/credential-and-payment-fraud trend threat rather than a software vulnerability: there is no CVE, no exploited software flaw, and no single centralized C2 infrastructure to dismantle. The actionable takeaway for defenders is that AI-assistant billing/subscription notifications are now a viable, actively-exploited phishing lure category that email security controls, security-awareness training, and brand-protection/anti-impersonation monitoring should explicitly account for going forward, alongside the long-established Microsoft/LinkedIn/Google/Apple/Amazon impersonation baseline.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1583 Acquire Infrastructure
- T1586 Compromise Accounts
- T1585 Establish Accounts
- T1587 Develop Capabilities
- T1566 Phishing
- T1684.001 Impersonation
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1528 Steal Application Access Token
- T1557 Adversary-in-the-Middle
- T1213 Data from Information Repositories
- T1102 Web Service
- T1105 Ingress Tool Transfer
- T1567 Exfiltration Over Web Service
- T1657 Financial Theft

## Sources

- [ChatGPT most impersonated brands - Infosecurity Magazine](https://www.infosecurity-magazine.com/news/chatgpt-most-impersonated-brands/)
- [The Phishing Paradox: The World's Most Trusted Brands Are Cyber Criminals' Entry Point of Choice - Check Point Blog](https://blog.checkpoint.com/research/the-phishing-paradox-the-worlds-most-trusted-brands-are-cyber-criminals-entry-point-of-choice/)
- [Microsoft tops brand phishing list in Q2 2026 report - IT Brief](https://itbrief.co.uk/story/microsoft-tops-brand-phishing-list-in-q2-2026-report)
- [Microsoft tops brand phishing list in Q2 2026 report - Security Brief Asia](https://securitybrief.asia/story/microsoft-tops-brand-phishing-list-in-q2-2026-report)
- [ChatGPT enters global ranking of most impersonated brands - BizCommunity](https://www.bizcommunity.com/article/chatgpt-enters-global-ranking-of-most-impersonated-brands-856883a)
- [Check Point Research: Microsoft Leads Q2 2026 Brand Phishing as ChatGPT Emerges as a New Phishing Target - IT Voice](https://www.itvoice.in/check-point-research-microsoft-leads-q2-2026-brand-phishing-as-chatgpt-emerges-as-a-new-phishing-target)
- [ChatGPT 'Update your payment details' phishing email leads to fake Stripe payment page - MailGuard](https://www.mailguard.com.au/blog/chatgpt-update-your-payment-details-phishing-email-leads-to-fake-stripe-payment-page?hs_amp=true)
- [Scam Alert: Fake OpenAI Subscription Email Requesting Payment Details - OpenAI Developer Community](https://community.openai.com/t/scam-alert-fake-openai-subscription-email-requesting-payment-details/1266793)
- [LinkedIn Still Number One Brand to be Faked in Phishing Attempts while Microsoft Surges up the Rankings to Number Two Spot in Q2 Report - Check Point Press Release](https://www.checkpoint.com/press-releases/linkedin-still-number-one-brand-to-be-faked-in-phishing-attempts-while-microsoft-surges-up-the-rankings-to-number-two-spot-in-q2-report/)
- [Scammers Most Likely to Impersonate DHL, Warns New Brand Phishing Report - Check Point Software](https://www.checkpoint.com/de/press-releases/scammers-most-likely-to-impersonate-dhl-warns-new-brand-phishing-report/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1665
