ChatGPT joins Microsoft's phishing nightmare as fake OpenAI scams surge
Your AI, their prey.

Hooked by AI. Image by Cybernews.
- ChatGPT entered the top 10 most impersonated brands for phishing for the first time, Check Point reported.
- OpenAI accounted for 1.1% of tracked brand phishing attempts, reflecting ChatGPT’s rapid mainstream adoption.
- Scammers spoofed ChatGPT Plus billing emails to steal users’ credit card details through fake payment pages.
- Check Point advised users to verify senders, avoid email links, and enable multi-factor authentication to reduce risk.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
ChatGPT has entered the top 10 most impersonated brands for the first time, according to Check Point's Q2 2026 Brand Phishing Report.
Branded phishing attempts might sound a bit old-school, especially given Microsoft’s name being commonly used in Windows scams in the 2000s and ensuing years.
Then there were the dodgy Facebook clicks, which a sizeable majority of the public became savvy to. Branded scams were feeling a bit outdated until hackers started posing as one of the AI giants to get with the times and modernize their approach.
OpenAI now accounts for 1.1% of all tracked brand phishing attempts, putting it alongside PayPal, WhatsApp, and Facebook.
That might not sound like a huge percentage, but it certainly puts ChatGPT on the map as a household brand, and one in which duplicitous behavior can be harnessed through.
For context, Microsoft remains the biggest phishing target at 23%, followed by LinkedIn, Google, Apple, and Amazon.
Together, those 5 brands account for more than half of all phishing campaigns, highlighting just how concentrated attackers' efforts are. The report suggests ChatGPT's rapid rise mirrors its explosive mainstream adoption.
Fake ChatGPT emails are stealing users' payment details
One phishing campaign spoofed ChatGPT Plus billing emails to trick users into handing over their credit card details by copying OpenAI branding and payment failure notifications to make the scam look legitimate.
Victims clicking the email were redirected to a fake payment page designed to harvest financial information. It was that easy.
"As AI tools move from novelty to daily habit... they become just as attractive a target as any bank or tech giant."
It found that most phishing attacks start with panic, fake payment failures, urgent security alerts, or account warnings designed to rush victims into clicking.
Users should type OpenAI's web address directly into their browser rather than following email links, the analysts advise.
Check Point says other common warning signs include distorted logos, broken buttons, suspicious domains, and fake social media links.
Check if your data has been leaked
A convincing-looking ChatGPT email isn't proof that it's genuine – the advice is to always verify the sender and destination URL. Enabling multi-factor authentication can still protect accounts even if passwords are stolen.
The irony is that AI itself is helping scammers produce polished phishing emails at scale, making scams harder than ever to spot.
If something looks or feels even slightly off, verify it through OpenAI's official website, not the message itself.