Kateryna Levytska
–
27 July, 12:20
ChatGPT was included for the first time in the list of brands most often copied by cybercriminals: in the top 10, OpenAI’s development was located next to such tech giants as Microsoft, Google, and Apple.
According to Check Point’s Q2 2026 Brand Phishing Report, ChatGPT accounted for 1.1% of all recorded brand impersonation phishing attacks. While that’s a small number, it’s still the chatbot’s first appearance in the top 10 and evidence that scammers’ interest in it continues to grow.

In terms of the number of attacks, OpenAI’s product is roughly on par with PayPal (1.3%), WhatsApp (1.4%), and Facebook (1.9%). At the same time, the service lags significantly behind the leader of the rating, Microsoft, where the main brand accounted for 22.6% and LinkedIn brought in another 11.6%.
Examples of attacks include fake emails claiming an error during a ChatGPT Plus payment. The message mimics OpenAI’s corporate identity but redirects victims to a fraudulent payment page with the aim of stealing their payment details. Ironically, it is AI tools that make it easier and faster to create such campaigns.
Overall, cybercriminals most often attacked technology companies, followed by social networks, and then banking applications.
Despite the changes in the list, the basic method of phishing campaigns remains the same: attackers use well-known company names, create a sense of urgency and try to force users to hand over passwords, personal information or payment details. Experts have traditionally advised not to open suspicious links and emails, as well as to protect accounts with access keys and multi-factor authentication.
Read also: A vulnerability in the email client allowed Russian hackers to attack NATO and Ukrainian organisations simply by viewing an email