SecurityBrief Canada - Technology news for CISOs & cybersecurity decision-makers
Canada
Microsoft tops brand phishing list in Q2 2026 report

Microsoft tops brand phishing list in Q2 2026 report

Thu, 23rd Jul 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Check Point has published its Q2 2026 Brand Phishing Report, which found Microsoft was the most impersonated brand in the quarter.

Microsoft accounted for 23% of all brand phishing attempts tracked in the period, well ahead of the next most copied brands. It retained the top spot among names attackers use to mimic trusted companies.

The top five impersonated brands were Microsoft, LinkedIn, Google, Apple and Amazon. Together, they made up more than half of all brand phishing attempts observed during the quarter.

That concentration suggests attackers are focusing on a relatively small group of widely used brands. Technology was the most targeted sector overall, followed by social networks and banking.

Top targets

ChatGPT entered the top 10 most impersonated brands for the first time, pointing to growing criminal interest in AI services that users increasingly rely on for subscriptions, payments and work tasks.

One example in the report involved a fake ChatGPT Plus billing email designed to resemble an OpenAI payment failure notice. Users who followed the message were taken to a payment page built to collect full credit card details.

Examples from the quarter showed how broad brand phishing schemes have become. They ranged from spoofed payment alerts and fake login pages to replica shopping sites and malware disguised as a software update.

A fraudulent Michael Kors site copied what the report described as the full shopping experience, including browsing, cart and checkout pages, to collect payment information from people who believed they were making a real purchase.

Another case used a fake UNIQLO regional storefront in a market where the retailer does not officially operate. One clue was that the social media icons on the site did not link to UNIQLO's real accounts.

Common signs

Several examples relied on visual similarity rather than technical sophistication alone. A fake Apple iCloud login page in Russian used Apple branding and logo imagery, while its sign-in button did not function, indicating it may still have been under development.

A counterfeit PayPal login page looked close to the original service, but the logo appeared distorted. Such visual flaws may reflect the growing use of AI tools to generate brand assets for phishing attempts.

In a Microsoft-themed case, a bogus support page urged users to install an urgent Office security update. Instead of delivering software from Microsoft, the link led to a disguised executable file intended to start a malware infection.

Urgency was one of the most consistent tactics used in these campaigns. Payment failures, account warnings and required updates all aim to push users to act before they stop to inspect a message or website more closely.

Small errors were also common across many of the cases. Distorted logos, dead buttons, mismatched social links and web domains that did not quite match the genuine brand were recurring warning signs.

Check Point also pointed to a shift in how phishing pages are assembled. As more fraudulent content is generated with AI tools, subtle design inconsistencies are emerging as a fresh sign that a site or message may not be genuine.

Brand phishing remains effective because it depends on familiarity rather than novelty. Users are more likely to trust messages that appear to come from companies they already use, especially when those messages resemble routine account notices tied to work, shopping or payments.

Rather than spreading their efforts evenly across thousands of companies, scammers are concentrating on a small number of widely recognised names, where imitation is more likely to trigger a quick response.

Technology brands stood out because they often sit at the centre of a person's identity, communications and finances. Social networking and banking services ranked next, reflecting the value of accounts that hold professional connections, personal information and payment data.

The addition of ChatGPT to the top 10 shows how quickly newer digital habits are being folded into established fraud methods. AI platforms are now attracting the same kind of impersonation activity long directed at large technology groups, banks and online consumer brands.

Microsoft accounted for 23% of all brand phishing attempts tracked in Q2 2026, while the top five impersonated brands together represented more than half of the total activity recorded in the quarter.