23 Jul 2026 | Company news

Check Point Research: Microsoft leads Q2 2026 Brand phishing as ChatGPT emerges as a new phishing target

New Brand Phishing Report reveals cybercriminals are concentrating attacks around the world's most trusted digital, social, and have now added AI platforms
By Check Point Software Technologies

Johannesburg, SA July 23 2026 – Check Point Research (CPR), the Threat Intelligence arm of Check Point® Software Technologies Ltd. (NASDAQ: CHKP), a pioneer and global leader of cyber security solutions, today released its Brand Phishing Ranking for Q2 2026.

According to the latest findings, Microsoft remains the most impersonated brand, accounting for 23% of all brand phishing attempts during the quarter — nearly double the next-closest brand.

The findings also show that cybercriminals continue to exploit the trust users place in widely-used technology, social networking, banking and now AI platforms to steal credentials, payment details and personal information.

In Q2 2026, LinkedIn ranked second at 11.6%, followed by Google at 6.7%, Apple at 5.8% and Amazon at 5.2%. Together, the top five most impersonated brands accounted for more than half of all brand phishing activity tracked this quarter, underscoring how attackers are focusing on a small group of globally recognised platforms that people use and trust every day.

Notably, Open AI's ChatGPT made the top 10 list for the first time, marking a clear signal that AI tools are now firmly on cybercriminals' radar. As AI platforms become part of daily workflows for subscriptions, payments and workplace tasks, they are becoming attractive targets for phishing campaigns in the same way as established technology and financial brands.

By industry, Technology remained the most impersonated sector, followed by Social Networks and Banking, reflecting attackers' continued focus on platforms that hold users' identities, professional relationships and money.

Omer Dembinsky, Data Research Manager at Check Point Research said, "Brand phishing is entering a new phase where attackers are not only exploiting trust in household technology names, but also moving quickly toward the AI platforms people are beginning to rely on every day. As generative AI enables criminals to create more credible emails, cloned websites and fake digital experiences at scale, organisations must shift from reacting after compromise to preventing these threats before users ever engage with them."

Top 10 Most Imitated Brands in Phishing – Q2 2026

Microsoft – 22.6%

LinkedIn – 11.6%

Google – 6.7%

Apple – 5.8%

Amazon – 5.2%

Adobe – 3.8%

Facebook – 1.9%

WhatsApp – 1.4%

PayPal – 1.3%

ChatGPT – 1.1%

Real-World Phishing Campaigns Observed in Q2 2026 The Q2 2026 report highlights a wide range of brand phishing techniques, from fake payment failure notices to replica online stores, fraudulent login pages and malware disguised as software updates.

One campaign impersonated ChatGPT Plus through a fake subscription payment failure email that led victims to a page designed to steal full credit card details. Another campaign used a lookalike Michael Kors online store that replicated the shopping journey, including browsing, cart and checkout, to capture payment information under the appearance of a legitimate purchase.

Attackers also created a fake UNIQLO regional storefront in a market where the brand does not officially operate, with disconnected social media icons serving as one of the indicators of fraud. In another case, a fake Apple iCloud login page used Apple's logo and branding, while a non-functional sign-in button suggested the page may still have been under testing before a broader campaign.

The report also documented a near-identical PayPal login page with a distorted logo, which may indicate the use of AI-generated assets, and a fake Microsoft support page that pushed an urgent Office security update but delivered a disguised executable file instead.

Why Brand Phishing Is Becoming Harder to Spot

Brand phishing works because it transfers trust from a familiar organisation to a fraudulent message or website. Across Q2 2026 cases, attackers used urgency, realistic branding, lookalike domains, broken buttons, mismatched links and subtle visual flaws to lower user suspicion and drive faster action.

Generative AI is also changing the economics of brand phishing by helping attackers produce more convincing emails and fraudulent websites at scale, making both the volume and sophistication of these attacks likely to grow. With generative AI lowering the barrier to creating convincing fake websites, emails and digital experiences, brand phishing is becoming harder to detect and easier to scale. As trust becomes the primary target, organisations must assume these attacks will continue to grow in both volume and sophistication.

Follow Check Point on LinkedIn, X (formerly Twitter), Facebook, YouTube and our blog.

About Check Point Research Check Point Research provides leading cyber threat intelligence to Check Point Software customers and the greater intelligence community. The research team collects and analyzes global cyber-attack data stored on ThreatCloud to keep hackers at bay, while ensuring all Check Point products are updated with the latest protections. The research team consists of over 100 analysts and researchers cooperating with other security vendors, law enforcement and various CERTs.

About Check Point Software Technologies Ltd. Check Point Software Technologies Ltd. (www.checkpoint.com) is a leading AI-powered, cloud-delivered cyber security platform provider protecting over 100,000 organizations worldwide. Check Point leverages the power of AI everywhere to enhance cyber security efficiency and accuracy through its Check Point Platform, with industry-leading catch rates enabling proactive threat anticipation and smarter, faster response times. The comprehensive platform includes cloud-delivered technologies consisting of Check Point Workspace Security to secure the workspace, Check Point to secure the cloud, Check Point to secure the network, and Check Point Core Services for collaborative security operations and services.

Legal Notice Regarding Forward-Looking Statements This press release contains forward-looking statements. Forward-looking statements generally relate to future events or our future financial or operating performance. Forward-looking statements in this press release include, but are not limited to, statements related to our expectations regarding our products and solutions, our expectations regarding future growth, the expansion of Check Point's industry leadership, the enhancement of shareholder value and the delivery of an industry-leading cyber security platform to customers worldwide. Our expectations and beliefs regarding these matters may not materialize, and actual results or events in the future are subject to risks and uncertainties that could cause actual results or events to differ materially from those projected. The forward-looking statements contained in this press release are also subject to other risks and uncertainties, including those more fully described in our filings with the Securities and Exchange Commission, including our Annual Report on Form 20-F filed with the Securities and Exchange Commission on March 17, 2025. The forward-looking statements in this press release are based on information available to Check Point as of the date hereof, and Check Point disclaims any obligation to update any forward-looking statements, except as required by law.

Press contact
Tech Review
Check Point Research: Microsoft leads Q2 2026 Brand phishing as ChatGPT emerges as a new phishing target | Tech Review Africa