At a glance: AI chatbots are increasingly being abused for brand phishing, forcing organizations to prioritize preventive security measures instead of reacting to attacks.
In Q2 2026, Check Point Research documents that OpenAI’s ChatGPT appears for the first time with a 1.1 percent share among the ten most-imitated brands in phishing attacks. Microsoft remains the leader with 23 percent, followed by LinkedIn and Google.
In the second quarter of 2026, Microsoft reinforced its position as the most-imitated brand in brand phishing attacks. According to Check Point Research, 23 percent of all detected phishing attempts targeted the software company. The next-ranked brands are LinkedIn (11.6 percent), Google (6.7 percent), Apple (5.8 percent), and Amazon (5.2 percent). These five brands together account for more than half of all recorded worldwide phishing attacks.
ChatGPT from OpenAI appears in this statistics for the first time: With a 1.1 percent share, the AI chatbot ranks 10th on the top-10 list. Researchers documented concrete attack patterns in which attackers sent fake notifications of allegedly failed payments for ChatGPT Plus and linked to manipulated pages to steal credit card data. Alongside this, analysts observed imitated online shops (for example Michael Kors, Uniqlo), fake Apple iCloud login pages, and counterfeit PayPal logins with AI-generated visual distortions. The technology sector was the most affected industry overall, followed by social networks and the banking sector.
The manipulated websites regularly use artificially generated pressure to act through payment demands or alleged security warnings. Identifying features are deviating URLs, incomplete links, and visual inconsistencies in logos and buttons. Omer Dembinsky, Data Research Manager at Check Point Research, warns: Generative AI allows criminals to create credible emails, cloned websites, and counterfeit digital experiences at scale. Brand phishing has reached a new level as attackers not only exploit trust in established technology brands, but now also imitate AI chatbots that users increasingly rely on.
For prevention, security experts recommend: direct entry of target addresses in the browser instead of via links, verification of hyperlinks through mouseover checks, activation of multi-factor authentication, and the use of AI-powered email filtering methods at the organizational level. Check Point Research emphasizes that organizations must shift their focus: instead of responding only after successful attacks, they should prevent these threats proactively before users ever come into contact with them.
Source: www.it-daily.net · Published 28 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.