Logo
FrontierNews.ai

ChatGPT Now a Top Phishing Target as Scammers Weaponize AI's Popularity

ChatGPT has become a prime target for cybercriminals, entering the top 10 most impersonated brands in phishing attacks for the first time in the second quarter of 2026. As millions of people rely on OpenAI's chatbot for daily work and manage subscriptions through it, scammers are exploiting that trust to steal payment information and login credentials.

Why Are Scammers Targeting ChatGPT Now?

The shift reflects a broader pattern in cybercrime: attackers follow user behavior. Check Point, a cybersecurity firm that tracks phishing trends, observed a particularly convincing fake "ChatGPT Plus payment failed" email in June that mimicked OpenAI's official billing notices. The malicious message directed victims to a fraudulent page designed solely to harvest full credit card details.

"As AI tools move from novelty to daily habit for millions of people managing subscriptions, payments, and work tasks through them, they become just as attractive a target as any bank or tech giant. Expect AI platforms to keep climbing this list in future quarters," Check Point stated.

Check Point, Cybersecurity Research Team

This represents a significant shift in the threat landscape. ChatGPT's inclusion signals that attackers are increasingly targeting AI platforms as they become embedded in everyday workflows. The phishing ecosystem has historically focused on established tech giants, but the rapid adoption of AI tools has created new vulnerabilities.

Which Brands Remain the Biggest Phishing Targets?

While ChatGPT is newly in the top 10, other technology companies still dominate the phishing landscape. Microsoft remains the most impersonated brand overall, accounting for 23% of all phishing attempts in Q2 2026, nearly double the share of LinkedIn, which ranks second. Both platforms are owned by Microsoft. Google, Apple, and Amazon round out the top five, collectively accounting for over half of all phishing attempts.

The concentration of attacks on major tech platforms reflects their ubiquity in business and personal life. However, the emergence of ChatGPT in this list marks a turning point: as AI tools become more central to how people work and manage their finances, they become equally attractive targets for fraud.

How to Protect Yourself From AI-Related Phishing Attacks

  • Verify sender addresses carefully: Legitimate billing emails from OpenAI will come from official company domains. Check the full email address, not just the display name, as scammers often use lookalike addresses that differ by a single character.
  • Never click links in unsolicited emails: Instead of clicking a link in a suspicious billing notice, log into ChatGPT directly through your browser or the official app to check your account status and payment information.
  • Enable two-factor authentication: Adding an extra layer of security to your ChatGPT account makes it significantly harder for attackers to gain access even if they obtain your password through phishing.
  • Be skeptical of urgent payment language: Phishing emails often create artificial urgency by claiming your account will be suspended or your service will be interrupted. Legitimate companies typically give you time to resolve billing issues.
  • Report suspicious emails: Forward phishing attempts to OpenAI's security team and mark them as spam in your email client to help protect other users.

What Real Phishing Cases Look Like in 2026

Check Point's Q2 2026 Brand Phishing Report documented a range of sophisticated attacks beyond simple email scams. Real cases included cloned online stores that replicate entire checkout processes, fake login pages with AI-generated logos, and malware disguised as software updates. One particularly convincing example was a cloned Michael Kors storefront that replicated the complete checkout experience, and a fake UNIQLO store operating in a country where the brand doesn't even have a presence.

These attacks demonstrate that phishing has evolved beyond basic email tricks. Scammers now invest in creating convincing replicas of legitimate websites and services, making it harder for users to distinguish real from fake at a glance. The inclusion of AI-generated elements in some attacks suggests that bad actors are also leveraging AI tools to improve their phishing campaigns.

What Should Organizations Do to Combat This Threat?

Check Point recommends a multi-layered defense strategy for businesses and individuals. The approach focuses on stopping phishing messages before they reach inboxes, using AI-powered detection systems to catch brand impersonation and credential harvesting attempts, and consolidating email and workspace protection across platforms like Microsoft 365 and Google Workspace.

Organizations should also automate investigation and response processes so security teams can resolve genuine threats faster, rather than spending time manually reviewing every suspicious email. This is particularly important as the volume and sophistication of phishing attacks continue to increase.

The emergence of ChatGPT as a phishing target underscores a fundamental reality of cybersecurity: as technology becomes more valuable and widely used, it becomes a more attractive target for criminals. Users of AI tools should remain vigilant about protecting their credentials and payment information, while organizations should invest in robust email security and employee training to stay ahead of evolving threats.