Microsoft has become the single most impersonated brand in phishing attacks, accounting for 23% of all brand phishing attempts in the second quarter of 2026, according to new data from Check Point Research. The figure, published on July 23, nearly doubles the next closest brand and cements a grim reality for Windows 11, Outlook, and Microsoft 365 users: the company's trusted name is now the weapon of choice for credential theft, malware delivery, and financial fraud.

Check Point's quarterly Brand Phishing Report tracks which companies' identities are most frequently abused in phishing campaigns. In Q2, Microsoft led the list, followed by LinkedIn (11%), Google (6%), Apple (6%), and Amazon (5%). Together, Microsoft and LinkedIn—both owned by Microsoft—represented more than a third of all tracked impersonations. The report underscores a persistent truth: criminals gravitate toward the most recognisable brands, and no technology brand is more woven into daily digital life than Microsoft.

The danger isn't theoretical. Check Point researchers documented a specific campaign in which a fake Microsoft support page urged visitors to install an urgent Office security update. Instead of a legitimate patch, victims downloaded a disguised executable that could initiate a malware infection. It's a textbook example of how attackers turn sound security habits—like keeping software updated—into traps.

What the Numbers Actually Reveal

The 23% share doesn't mean one in four Windows users were phished. It means that when Check Point's telemetry identified a brand-impersonation attempt, Microsoft's name was used 23% of the time. The statistic is a measure of criminal preference, not victim count. And it's a preference born of opportunity: Microsoft's product portfolio spans Windows, Office, Outlook, OneDrive, Teams, Xbox, and the underlying Microsoft account that ties them together. A single fake "Microsoft security alert" can plausibly target hundreds of millions of people.

Check Point's ranking also shows the shifting tactics. ChatGPT entered the top 10 for the first time, with a fake payment‑failure email designed to steal credit card details. That arrival signals that as AI tools become mainstream, their brands join the impersonation roster. For a typical user who might receive legitimate emails from Microsoft, LinkedIn, Google, and an AI service like ChatGPT in a single morning, the attack surface is expanding fast.

The rest of the list—Adobe, Facebook, WhatsApp, PayPal—rounds out a familiar but sobering picture. Brand phishing is not a niche enterprise attack; it's a broad, consumer‑facing threat that uses the logos and language you see every day.

What the Surge Means for You

If you use Windows, Outlook, or any Microsoft 365 service, the report's top line is straightforward: you are almost certainly being targeted, even if you haven't noticed. The most dangerous phishing messages no longer come with spelling mistakes and blurry logos. They mimic the exact design of a real Microsoft password‑expiry notice, a shared OneDrive file, a Teams voicemail, or an invoice from a service you might actually use.

For home users

A fake Outlook mailbox‑quota warning lands in your personal inbox, complete with a blue "Verify account" button. The link takes you to a site that looks identical to the Microsoft login page. Enter your credentials, and the attacker now controls your email—and possibly your Windows sign‑in if you use the same Microsoft account. From there, they can reset passwords for other services, search your OneDrive for sensitive documents, or lock you out entirely.

Another common lure: a pop‑up while browsing that mimics a Windows blue screen warning of a virus, with a toll‑free number to call. Microsoft does not include phone numbers in error messages. Real alerts never demand that you call a number or download software from a random website. Yet these scams persist because they trigger fear and urgency.

For business and enterprise users

An HR‑department email appears to share a "2026 salary adjustment" Excel file via SharePoint, requiring a Microsoft 365 login. Or a Teams message arrives: "You have a new voicemail—listen here." In a busy workday, these blend into the legitimate flow of collaboration. One compromised credential can give attackers a foothold inside a corporate network. And if the target holds administrative privileges, the breach can escalate quickly.

Check Point's fake Office update example is especially relevant here. Many organisations instruct employees to install all updates promptly. An email that says "Critical security patch for Microsoft 365 Apps—install immediately" can bypass a user's skepticism precisely because it echoes corporate policy.

For IT administrators

The report is a reminder that user education and technical controls must work in tandem. Microsoft 365's built‑in anti‑phishing features—spoof intelligence, impersonation protection, Safe Links, and machine‑learning‑based detections—are solid. But no filter catches everything. Attackers rotate domains, tweak language, and shift to new hosting providers continuously. When a campaign does slip through, it's the user's split‑second decision that determines the outcome.

How We Got Here: Familiarity as an Attack Surface

Microsoft has topped Check Point's brand‑phishing rankings for several quarters. The trend reflects not a sudden vulnerability in Windows or Outlook but a persistent criminal strategy: social engineering at scale. As email providers improve spam filters and browsers flag malicious sites, attackers lean harder on the one element that remains exploitable—human trust.

Microsoft's dominance in productivity software makes its branding especially valuable. A phishing email about a fake Office 365 invoice, a OneDrive file share, or a Teams meeting invite leverages the daily rhythms of modern work. The company's consumer reach amplifies the risk: hundreds of millions use Outlook.com, Xbox Live, and Windows sign‑in. The same blue logo that reassures a user during a genuine password reset is easily copied to deceive.

The COVID‑era shift to remote work accelerated the problem. Workers who rarely saw IT staff in person became more reliant on email and chat for support, and attackers capitalised on that abstraction. Over the past two years, Microsoft and other major brands have been used in campaigns that combine phishing with vishing (voice phishing) and smishing (SMS phishing), creating multi‑channel pressure on targets.

Check Point's inclusion of ChatGPT as a top‑10 brand for the first time suggests a new frontier. As AI becomes a daily tool, its associated login pages, billing portals, and update prompts become fresh templates for fraud. Windows users who also rely on AI services now face impersonation risks from two sides.

What to Do Now: A Practical Defense Routine

The most effective countermeasure isn't a single product; it's a set of habits that remove the attacker's chief advantage—speed. When a message demands immediate action, pause. Follow these steps every time you encounter an unexpected alert, invoice, shared file, or update prompt bearing Microsoft's name.

If an email says your account is locked, your password expired, or your mailbox is full, do not click the provided button. Open a browser and go directly to the Microsoft account portal (account.microsoft.com), Office.com, or your organisation's known sign‑in page. If the notification was legitimate, you'll see the same alert there. If it wasn't, you've just avoided a credential‑stealing page.

2. Hover before you click

On a PC, hover your mouse over any link to see the true destination in the status bar. On a mobile device, long‑press the link. A label reading "Sign in to Microsoft" might actually point to a domain like "microsoft‑verify.com" or "office-365‑support.net". Look for subtle misspellings, extra hyphens, or unfamiliar top‑level domains (.co, .xyz, .support). Microsoft's official domains are predictable: microsoft.com, office.com, outlook.com, onedrive.com, teams.microsoft.com, and a handful of others. Any deviation should trigger alarm.

3. Treat attachments with extreme caution

Legitimate updates for Windows, Office, or Edge never arrive as email attachments. Do not open .exe, .msi, .bat, .scr, or password‑protected .zip files from unsolicited messages. Microsoft will never ask you to disable security settings, enable macros, or run a script to read a document. The fake Office update described in Check Point's research highlights why this rule is non‑negotiable: real patches come from Windows Update or the vendor's official site, not an email link.

4. Enable multifactor authentication (MFA)

A stolen password is useless if it requires a second factor to sign in. Microsoft accounts, Microsoft 365, and most enterprise services support MFA via authenticator apps, SMS, or hardware keys. Turn it on. While MFA doesn't block every attack—some advanced phishing kits can intercept session tokens—it stops the vast majority of credential‑stuffing attempts that follow a successful phish.

5. Use the reporting tools built into Outlook and Edge

When a phishing message lands in your Outlook inbox, select it and choose Report > Report phishing. This removes the message from your inbox and sends metadata to Microsoft's filters, helping protect others. If you encounter a suspicious website in Edge, go to Settings and more (…) > Help and feedback > Report unsafe site. Reporting only takes seconds and improves detection for the entire ecosystem.

6. Know the signs of a tech‑support scam

Any pop‑up, browser page, or email that displays a phone number and urges you to call for technical support is a scam. Microsoft's support channels are initiated by you—not the other way around. Real error messages never contain toll‑free numbers, and Microsoft does not make unsolicited calls about malware or account issues. If a full‑screen alert claims your PC is infected and demands a call, use Alt+F4 or Task Manager to close the browser, then run a quick scan with Windows Security.

What to Watch Next

Check Point's report makes clear that brand phishing is not a seasonal problem; it's a permanent feature of the threat landscape. As more services integrate AI assistants and cloud‑based productivity tools, the number of trustable brands that criminals can imitate will grow. Expect to see phishing kits that combine Microsoft, LinkedIn, and ChatGPT lures in a single campaign, aiming to snatch a work credential at 9 a.m. and a credit card at 2 p.m.

Microsoft, for its part, continues to invest in AI‑driven defenses and has expanded its Secure Future Initiative, but the company's own advice remains clear: user vigilance is the last line of defense. The Q2 2026 data doesn't signal a new vulnerability; it signals that an old, effective attack strategy remains the preferred weapon of cybercriminals—and that your inbox is where the battle is fought.