Insights into Brand Phishing for Q2 2026
Check Point Research has published its brand phishing report for the second quarter of 2026, shedding light on alarming trends in cyber threats. With Microsoft still in the spotlight, representing 22.6% of brand phishing incidents, it continues to be the most impersonated brand. This report essentially highlights how cybercriminals exploit the trust associated with major technology and financial platforms, stealing sensitive information such as login credentials and payment data.
In this quarter, LinkedIn followed with 11.6%, while Google, Apple, and Amazon had shares of 6.7%, 5.8%, and 5.2%, respectively. These top five brands account for over half of the phishing activities within this timeframe, revealing that attackers are concentrating their efforts on a limited number of globally recognized platforms that people frequently use.
The Rise of AI Platforms
One notable revelation from this report is the entry of OpenAI’s ChatGPT into the top ten most impersonated brands, with a phishing incidence rate of 1.1%. As AI tools become integrated into daily subscriptions and business tasks, they are being increasingly targeted by phishing campaigns, paralleling the existing technology and financial brands. This surge underscores a growing concern for cybersecurity as attackers expand their focus from traditional sectors to emergent ones like artificial intelligence.
Continuing with sector-based analysis, the technology sector remains the prime target for phishing, followed closely by social networking and banking industries. This indicates that attackers are still keenly focused on platforms that manage user IDs, professional connections, and financial assets.
Omer Dembinsky’s Insights
Omer Dembinsky, Data Research Manager at Check Point, emphasized, "Brand phishing has entered a new phase, with attackers not only exploiting the trust of familiar tech brands but also broadening their targets to include AI platforms that increasingly permeate daily life. Now, criminals can leverage generative AI to create more convincing emails, counterfeit sites, and deceptive digital experiences on a large scale. Consequently, organizations must shift from a reactive approach to a proactive stance that prevents users from encountering threats in the first place."
Detailed Breakdown of Phishing Incidents
The report details the brand phishing incidents that occurred during Q2 2026. The ranking of the most impersonated brands showcases distinct phishing categories used by criminals:
1.
Microsoft - 22.6%
2.
LinkedIn - 11.6%
3.
Google - 6.7%
4.
Apple - 5.8%
5.
Amazon - 5.2%
6.
Adobe - 3.8%
7.
Facebook - 1.9%
8.
WhatsApp - 1.4%
9.
PayPal - 1.3%
10.
ChatGPT - 1.1%
Sophisticated Phishing Tactics
During this quarter, diverse phishing techniques were reported, including deceptive false payment failure notifications, imitation online stores, and malware disguised as software updates. One specific attack tactic that impersonated ChatGPT Plus involved sending payment failure notifications that led victims to pages aiming to harvest credit card information. Another campaign imitated a legitimate-looking Michael Kors online store to trick users into entering their payment details during a seemingly official purchase flow.
Additionally, phishing schemes masquerading as brands like UNIQLO sought to target markets where these brands did not officially operate, using fake storefronts and misleading social media icons as red flags. The report also documents a fraudulent Apple iCloud login page that utilized Apple’s branding, potentially serving as a trial phase before launching a wider phishing campaign.
Moreover, a log-in page closely resembling PayPal was also identified; it exhibited distorted logos, indicating the potential use of AI-generated material. A further incident involved a fake Microsoft support page purporting to distribute software updates under the guise of major security alerts.
The Growing Challenge of Detection
Brand phishing is becoming increasingly sophisticated, leveraging the inherent trust consumers have in familiar organizations to add credibility to their malicious messages and websites. Across the various incidents included in the report, attackers utilized urgency, realistic branding, and similar domains to lower user suspicions and prompt swift actions. However, several cases did reveal botched functionality, such as nonworking links and subtle design flaws in their images.
The economic implications of generative AI are shifting brand phishing dynamics, allowing attackers to create persuasive emails and imitation sites effectively and at a lower cost. The ease of producing credible counterfeit experiences has made brand phishing more challenging to detect and capable of scaling more rapidly. With trust itself becoming a primary target, organizations need to prepare for these attacks to grow in both frequency and sophistication effectively.
About Check Point Research
Check Point Research serves customers and the threat intelligence community by providing the latest insights into cyber threats. They analyze data on cyberattacks stored within Check Point’s ThreatCloud AI, focusing on preventing hackers while ensuring the efficacy of the protection features embedded in their products. With a team of over 100 analysts and researchers, they work in conjunction with security vendors, law enforcement agencies, and various CERT organizations to bolster cybersecurity measures.
For more information, please visit
Check Point Blog or
Check Point Research Blog.