Check Point’s latest Brand Phishing Report, covering the second quarter of 2026, found Microsoft impersonated in 23% of all brand phishing attempts tracked globally, nearly double any other brand. Microsoft, LinkedIn, Google, Apple, and Amazon between them account for over half of all brand phishing activity this quarter. The notable new entry: ChatGPT has appeared in the top ten impersonated brands for the first time, a sign that AI platforms are now mainstream enough to be worth faking.
This matters directly for UK SMEs because Microsoft 365 is the productivity backbone of most small businesses, meaning a fake “your Microsoft account needs attention” email lands in an inbox where the real version of that message is completely routine. Attackers are counting on staff being too used to genuine Microsoft prompts, sign-in alerts, storage warnings, subscription renewals, to scrutinise the fake ones. The same logic now applies to ChatGPT: as more employees use it daily for work, a fake “your ChatGPT subscription payment failed” email reads as ordinary rather than suspicious.
How the fakes actually work
Check Point’s researchers flagged a consistent playbook: urgency-driven subject lines about payment failures or required security updates, replica login pages and checkout screens that are near-indistinguishable from the real thing, and increasingly, AI-generated visual assets with only subtle distortions giving them away. Domain spoofing, slightly altered URLs or unusual extensions, remains the final trick that catches people who’ve correctly spotted everything else but click through anyway.
What to actually do about it
Never click a link in an email claiming to be from Microsoft, Google, or any major platform. Type the address in directly. This single habit defeats the majority of the replica-page tactic outright, because the fake page is only dangerous if you land on it via the email’s link.
Treat AI tool notifications with the same suspicion as banking emails now. ChatGPT joining the top ten means “AI platform” is no longer a category staff can assume is too new or niche to be worth faking. If your team uses ChatGPT, Copilot, or Gemini for work, brief them the same way you’d brief them on a fake bank email.
Run a dark web and lookalike-domain check if you haven’t recently. Attackers registering domains that look like yours, or like the brands your customers associate with you, is often invisible until someone reports being scammed by it. KeepSafe runs this kind of monitoring continuously so a lookalike domain or leaked credential set gets caught before it’s used against your customers, not after.
Turn on multi-factor authentication everywhere it’s offered, and don’t treat it as optional for “less important” accounts. Check Point’s advice to apply it universally exists because attackers specifically target whichever account in a business has the weakest protection, then pivot from there. The finance inbox is an obvious target, but so is the shared marketing login or the account nobody remembers setting up.
Why the fakes keep getting better
Part of what makes this quarter’s report notable is the acknowledgment that AI-generated phishing assets are now good enough that the old advice, “look for bad grammar and obvious logo errors”, is no longer reliable on its own. The visual distortions Check Point flags are subtle: a button that’s slightly the wrong shade, a font that’s almost but not quite right, a layout copied convincingly but not pixel-perfect. That’s a genuine shift from a few years ago, and it means training staff to spot phishing by appearance alone is a shrinking strategy. The habit that still works regardless of how good the fake looks is the behavioural one: go direct, don’t click through.
The takeaway
Brand phishing works precisely because the fake looks exactly like the real, routine email your team already trusts. With Microsoft still the top target and ChatGPT now on the list, the safest default for any account-related email is the same one: don’t click, go direct, and check independently if you’re not sure.