For years, the phishing playbook barely changed, spoof Microsoft, spoof your bank, spoof the courier company waiting on a "failed delivery." This quarter, that playbook got a new entry, and it's one most CIOs didn't see coming: ChatGPT.
According to Check Point Research's Q2 2026 Brand Phishing Ranking, OpenAI's chatbot has entered the top 10 most impersonated brands globally for the first time, right alongside long-time regulars like Microsoft, LinkedIn, Google, Apple, and Amazon. One widely observed campaign impersonated a ChatGPT Plus subscription renewal, warning users their payment had failed and pushing them toward a fake page built purely to harvest full credit card details.
Microsoft's own threat intelligence team has been tracking similar activity for months, documenting look-alike campaigns built around ChatGPT, Copilot, DeepSeek, and Anthropic's Claude. In one case tracked back to early May, roughly 4,500 emails warning of a ChatGPT Plus downgrade were sent to targets in South Africa alone, routing victims through multiple legitimate-looking redirects, a CRM link, an Amazon tracking domain, a URL shortener, before landing on a compromised page hiding behind a fake CAPTCHA. Crucially, none of this reflects any actual breach of OpenAI's own systems, it's the brand's trust being borrowed, not its infrastructure being broken into.
For enterprise security teams, the shift matters because AI tools have quietly become part of daily workflows for subscriptions, payments, and everyday tasks, exactly the kind of routine, trusted interaction phishing thrives on exploiting. Employees who've grown comfortable clicking "update payment method" for dozens of SaaS tools now have one more familiar-looking brand to second-guess.
The lesson for CIOs isn't really about ChatGPT itself, it's a reminder that trust, once built at scale, becomes the next attack surface, whichever platform earns it.
Filed by
Startup Unplugged



