Microsoft and LinkedIn Among Top Brands Targeted in Phishing Scams: 2026 Report
A Check Point Software report reveals that major tech brands were the most exploited in phishing attacks during Q2 2026, with Microsoft (22.6%), LinkedIn (11.6%), and Google (6.7%) leading the list. Criminals abuse user trust in well-known companies to steal credentials and financial data through fake emails and cloned websites. ChatGPT appeared for the first time in the top targets, indicating AI services are becoming new phishing vectors.
Overview of the Scam
A Check Point Software report reveals the scope of phishing attacks in Q2 2026, with major technology companies being the most exploited. Over 50% of phishing attempts targeted just five companies: Microsoft, LinkedIn, Google, Apple, and Amazon.
How This Scam Works
Brand impersonation phishing uses fake emails, cloned websites, and fraudulent communications to deceive users. Criminals exploit the trust people have in familiar companies to steal passwords, personal information, and payment data.
Most Targeted Brands (Q2 2026):
- Microsoft: 22.6%
- LinkedIn: 11.6%
- Google: 6.7%
- Apple: 5.8%
- Amazon: 5.2%
- Adobe: 3.8%
- Facebook: 1.9%
- WhatsApp: 1.4%
- PayPal: 1.3%
- ChatGPT: 1.1%
Criminals target well-known brands because people use them daily, making fraudulent emails appear legitimate. The technology sector is most vulnerable because it holds multiple accounts, digital identities, and sensitive data.
ChatGPT Enters the Rankings
ChatGPT's first appearance on the list is significant. One documented case involved a fake payment failure notice for ChatGPT Plus that directed users to a credential-harvesting page. This shows AI-related services are becoming new phishing targets.
Warning Signs and How to Identify Fraud
Even sophisticated phishing attempts leave clues:
- Distorted logos or low-quality images
- Broken buttons or non-functioning links
- URLs that closely resemble official addresses but differ slightly
- Spelling errors or messages with excessive urgency
Warnings about payment failures, mandatory updates, or security issues often pressure people to act without verification—a tactic fraudsters rely on.
Prevention Tips
-
Avoid Clicking Links: Do not click links in suspicious messages. Instead, navigate directly to the official website by typing the address into your browser.
-
Enable Two-Factor Authentication: This adds a security layer that can prevent unauthorized access even if your password is compromised.
-
Verify the Sender: Carefully check the email address, company name, and writing style for inconsistencies.
-
Contact Directly: Rather than using contact information in emails, use phone numbers or email addresses from the official company website.
-
Check URLs Carefully: Hover over links to see the actual destination before clicking. Official company domains should be exact matches.
Where to Report
If you suspect phishing or become a victim, report it to:
- Your local law enforcement agency
- Cybercrime reporting centers in your country
- The company being impersonated
- Your email or social media platform
Source: Olhar Digital