ChatGPT Has Become One of the Top 10 Brands Most Frequently Impersonated in Phishing Attacks

26.07.2026 3 minutes Author: Newsman

ChatGPT has entered the top 10 most impersonated brands for the first time, as cybercriminals increasingly exploit its popularity in phishing campaigns. Researchers say the rapid adoption of the service has made the OpenAI brand an attractive lure for stealing users’ payment information and account credentials.

According to Check Point’s Brand Phishing Report for the second quarter of 2026, OpenAI now accounts for 1.1% of all recorded brand phishing campaigns. The company has entered the top 10 most impersonated brands for the first time, joining the likes of PayPal, WhatsApp, and Facebook.

Just a few years ago, most phishing attacks revolved around Microsoft and Facebook. Cybercriminals routinely abused the popularity of Windows and social media platforms, but with the rise of generative AI, they have quickly shifted their tactics. Today, OpenAI users are increasingly becoming the target of these scams.

Despite ChatGPT’s debut in the rankings, Microsoft remains the most impersonated brand, accounting for 23% of all phishing campaigns. It is followed by LinkedIn, Google, Apple, and Amazon. Together, these five brands are used in more than half of all brand phishing attacks, highlighting how heavily cybercriminals concentrate on the world’s most popular digital services.

One of the most common campaigns involves fake ChatGPT Plus payment emails. Victims receive messages claiming that their subscription payment has failed, with emails carefully designed to mimic OpenAI’s branding and legitimate payment notifications.

Users who click the embedded link are redirected to a fraudulent payment page, where they are prompted to re-enter their credit card details. Any information submitted is immediately captured by the attackers.

“As AI tools evolve from a novelty into an everyday habit, they become just as attractive a target as any bank or major technology company.”

Researchers note that these attacks rely heavily on psychological pressure. Fraudsters attempt to create a sense of urgency through fake payment failures, security alerts, or account suspension warnings, pushing victims to click links without thinking.

Security experts recommend never accessing OpenAI through links included in emails. Instead, users should manually type the official website address into their browser and verify their account directly.

They also advise watching for common warning signs, including distorted logos, broken buttons, suspicious domain names, fake social media links, and unusual sender addresses. Even if an email looks convincing, it should never be assumed to be genuine.

Researchers further recommend enabling multi-factor authentication. Even if a password is stolen, it can provide an additional layer of protection that prevents attackers from gaining access to an account.

Ironically, artificial intelligence itself is now helping cybercriminals produce increasingly polished and convincing phishing emails at scale, making fraudulent messages harder than ever to distinguish from legitimate ones.

If an email or message raises even the slightest suspicion, the safest approach is to visit OpenAI’s official website directly rather than following any links included in the message.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.