Be careful where you click — ChatGPT joins Microsoft, Google in most-impersonated brands online

Security News

Be careful where you click — ChatGPT joins Microsoft, Google in most-impersonated brands online

Credit: The original article is published here.
  • OpenAI now accounts for 1.1% of all tracked brand impersonations, ranking top 10
  • Microsoft and LinkedIn still account for a joint 34.2% of all impersonations
  • Basic cybersecurity hygiene can prevent many attacks

New research from Check Point has revealed ChatGPT is becoming increasingly targeted in brand phishing attempts, with the company now appearing in the top-10 list alongside heavy hitters like Microsoft, Google and Apple.

Though ChatGPT only accounted for 1.1% of all tracked brand phishing attempts, this marks the first time it’s appeared in the top-10 and reflects continued growth for attackers.

It sees a similar number of attacks to PayPal (1.3%), WhatsApp (1.4%) and Facebook (1.9%), but at present, it’s far behind Microsoft, which when combined with its LinkedIn subsidiary, accounts for more than a third (34.2%) of all tracked brand impersonations.

ChatGPT is growing as an impersonated brand

One example from the second quarter of this year saw fake ChatGPT Plus payment failure emails copying OpenAI’s branding, but directing victims to a fraudulent payment page to maliciously collect their payment information.

As for Microsoft, fake support pages warned customers that they needed to update Office for security fixes, but the download actually installed malware on victim devices.

Attacks on OpenAI are fairly ironic, because it’s likely to company’s own AI tools (among plenty of others) that actually helped attackers to write many of the attacks at lightning pace.

Overall, tech companies were targeted most, followed by social media platforms in a similar vein, and then banking apps.

Despite fluctuations in terms of which brands are targeted and how campaigns look, the general attack vector remains unchanged, with cybercriminals targeting vulnerable users and emphasizing urgency to trick people out of sharing information, credentials and payment details.

Security experts warn potential victims to be weary of clicking on unknown URLs and opening unexpected communications, as well as to protect their accounts with passkeys and secure multi-factor authentication (MFA).

Google logo on a black background next to text reading 'Click to follow TechRadar'

Leave a Reply

Your email address will not be published. Required fields are marked *