The Fake CAPTCHA Scam (ClickFix): A Plain-Language Warning for Private Practices

Tech News Private practice security

The fake CAPTCHA scam: how “verify you’re human” can install malware on your computer

There is a fast-growing scam that turns a familiar internet habit against you. It looks like a normal “prove you’re not a robot” check, but it walks you through steps that quietly install malware, and you do the installing yourself. Here is how to recognize it, the one rule that stops it cold, and exactly what to do if you already followed the steps.

The one rule that stops this scam
A real CAPTCHA never asks you to leave your browser, open a system tool, or paste and run a command. If a “verification” step tells you to press Windows + R, open Terminal or PowerShell, or paste anything with Ctrl + V and press Enter, it is not a CAPTCHA. Close the tab.
If you remember nothing else from this article, remember that. Everything below explains why it works and what to do.

The short version

  • It is called ClickFix. Security researchers and the US Federal Trade Commission, which issued a fresh warning in June 2026, use this name for the fake CAPTCHA scam.
  • You install the malware, not the hacker. The page tricks you into running a command yourself, which is why antivirus often does not catch it.
  • It is everywhere now. It shows up on hacked legitimate websites, in search ads, and on spoofed pages, not just sketchy corners of the internet.
  • The giveaway is Ctrl + V. A paste command has no business appearing in any human-verification step.
  • For a practice, the stakes are higher. The malware steals saved passwords and logins, which can mean exposure of email, client records, and everything else you can reach from your device.
01

What this scam is

You have solved thousands of CAPTCHAs. That is exactly the habit this scam exploits.

A real CAPTCHA asks you to do something small inside your browser: type some distorted letters, or click every square with a traffic light. That is it. It never asks you to leave the page or run anything on your computer.

The fake version copies that familiar look. It shows a counterfeit “security verification” box, often made to look like the Cloudflare or Google verification screens you already trust. But instead of a normal puzzle, it gives you a short list of keyboard “steps” to complete. Those steps quietly open a system tool and run a command the scam already slipped onto your clipboard. The FTC issued a consumer warning about this in June 2026.

Security researchers call it ClickFix, because many versions start with a button that says something like “Fix it” or “How to fix.” It has been spreading since 2024 and surged through 2025 and 2026. According to reporting on Microsoft’s tracking, ClickFix activity rose sharply and now accounts for a large share of the intrusions researchers see.

02

How it works, step by step

The whole scam is built out of normal-looking actions, which is what makes it effective. Here is the sequence.

1
You land on a page with a “verify you’re human” boxYou clicked a search result, an ad, a link, or a normal website that has been quietly hacked. A verification overlay appears. It looks routine.
2
It says verification “failed” and gives you steps to fix itInstead of a puzzle, it tells you to complete a few keyboard steps to continue. The instructions look simple and official.
3
A hidden command is copied to your clipboardThe moment you click the button or start the steps, malicious code on the page silently places a command on your clipboard. You cannot see this happen.
4
You are told to open a system tool and pasteOn Windows: press Windows + R to open the Run box, then Ctrl + V to paste, then Enter. On a Mac: open Terminal and paste. Pressing Enter runs the hidden command.
5
The malware installs itself, quietlyBecause you ran it yourself, no download warning appears and no “are you sure?” prompt pops up. The command downloads and installs the real malware in the background.

What these look like in the real world

These are not hypothetical. Below are reproductions of two real fake CAPTCHA prompts, the Windows version and the Mac version. Notice how ordinary they look, and how the dangerous steps are dressed up as routine “verification.”

Real scam · Windows The “I’m not a robot” button copies a hidden command. The steps then tell you to open the Run box (Win+R), paste it (Ctrl+V), and run it (Enter).
Real scam · Mac The Mac version uses Terminal instead of the Run box. The blurred section plus | base64 -D | bash is a command that decodes and runs hidden code. No real CAPTCHA shows you a terminal command.
The pattern is identical on every device Open a system tool, paste, press Enter. Windows uses the Run box, Mac uses Terminal, but the trick is the same. The words around it (“verification,” “prove you are human,” “VERIFY”) are there to make a dangerous action feel routine.
03

How to spot it: real versus fake

You do not need to be technical to catch this. The difference between a real verification and the scam is simple and consistent.

A real CAPTCHA Click images, type distorted letters, or tick an “I’m not a robot” box. Everything stays inside the browser page.
The fake one Tells you to press keyboard shortcuts, open a system tool, paste a command, or run something to “fix” a problem.
!
The biggest red flag: Ctrl + V Pasting has no place in a human check. If you are told to paste anything, stop. Something was already copied for you.
!
“Win + R,” “Terminal,” “PowerShell” Any instruction to open one of these system tools during a “verification” is the scam, every time.
If you see this, do this Close the tab. Do not finish the steps. You can safely leave the page. Nothing bad has happened yet as long as you have not opened a system tool and pressed Enter. If you are unsure whether a verification is real, the safe move is always to close it and navigate to the site directly.
04

Why it slips past antivirus

This is the part that surprises people, and it is worth understanding so you take the threat seriously. Most malware gets caught because it arrives as a suspicious file or download that security software can inspect and block. This scam avoids all of that.

Because you are the one running the command, using tools that already come built into your computer, there is no suspicious attachment, no risky download, and no browser warning to trigger. As one security firm put it, the attack turns the user into the way in. That is exactly why awareness, not software alone, is the strongest defense here.

Plain-language translation Think of it like a burglar who, instead of breaking a window, convinces you to open the front door and carry their bag inside. Your alarm system never goes off, because from its point of view, you let them in. The fix is not a better alarm. It is knowing not to open the door.
05

Why a private practice is worth targeting

The malware these scams install is usually an “infostealer” or a remote-access tool. In plain terms, it hunts for saved passwords, browser logins, session cookies, and financial details, and it can give an attacker ongoing access to your device.

For a clinician, that reaches further than your own bank account. If your browser has saved logins for your email, your practice management or EHR system, your client scheduling, or your billing, those are exactly what this malware looks for. A single moment of pasting a command can put protected health information and your clients’ trust at risk.

For practices handling client data If you work with protected health information, a malware infection is not only a personal problem. It can become a privacy and compliance event. This is general guidance, not legal advice, but if you suspect your work device was compromised, treat it seriously, involve IT support or a professional promptly, and review your breach-response obligations under HIPAA and your website security standards.
06

What to do if you already clicked

If you ran the command, or you noticed something downloading right after a “CAPTCHA,” act now rather than waiting to see what happens. Weeks can pass between the moment the malware lands and the moment damage shows up, so speed matters. The following steps reflect guidance from the FTC and the Identity Theft Resource Center.

1
Disconnect from the internet right awayTurn off Wi-Fi or unplug the network cable. This cuts the attacker off from your device and accounts while you clean up.
2
If it is a work device, tell your IT support immediatelyLet whoever handles your practice’s technology know before doing anything else, so they can help contain it.
3
Run a full security scan, or take it to a professionalUse trusted antivirus or anti-malware software to scan and remove threats. If you do not have any, have a professional check the device.
4
Change your passwords from a different, clean deviceDo not type passwords on the affected computer. Start with email, banking, and any client or practice systems. Turn on two-factor authentication.
5
Watch your accounts for several weeksCheck financial and practice accounts for unfamiliar activity and logins from unexpected places.
6
Report it to the FTCFile at ReportFraud.ftc.gov. Reporting helps authorities track and disrupt these campaigns.
Do not wait it out The instinct to “see if anything actually happens” is the wrong move here. The safest assumption is that something was installed, and the steps above limit the damage. There is no harm in acting even if it turns out you were fine.
07

How to protect yourself and your practice

A few simple habits make you and your team very hard to catch with this scam. These apply whether you are a solo clinician or have a small group practice.

Learn the one rule, and teach your teamNo website should ever ask you to run a command. Make sure everyone who touches a practice device knows the Win+R and Ctrl+V red flags.
Be extra careful with search ads and unfamiliar linksAttackers buy ads so people searching for normal software land on fake pages. When in doubt, type the address yourself rather than clicking a link.
Keep your system, browser, and security software updatedUpdates close other doors, even though this particular scam relies on tricking you rather than exploiting software bugs.
Turn on two-factor authentication everywhereEspecially email and any client or billing systems. It limits the damage if a password is ever stolen. Prefer an authenticator app over text messages.
Be cautious about saving sensitive logins in your browserBrowser-saved passwords are a top target for this malware. A dedicated password manager like Bitwarden or 1Password is generally safer.
When something feels off, slow downThis scam relies on routine and speed. A few seconds of “wait, why is a CAPTCHA asking me to do this?” defeats it completely. Skepticism is the defense.
08

Frequently asked questions

I closed the tab but did not run anything. Am I infected?
No. The malware only installs if you open a system tool (like Run, Terminal, or PowerShell), paste the command, and press Enter. Simply seeing the fake page, or even clicking the “fix” button, copies a command to your clipboard but does not run it. If you closed the tab without running anything, you are fine. To be safe, clear your clipboard by copying some ordinary text.
Does this only affect Windows?
It started on Windows and is most common there, using the Run dialog. But Mac versions exist too, using Terminal, and have been in active circulation since 2025. The same rule applies on every device: a verification step should never ask you to open a system tool or run a command.
Will my antivirus catch it?
Often not, at least not at the moment you run the command. Because you execute it yourself using built-in system tools, there is no suspicious download for antivirus to flag. Some security software may catch the later stages, but you should never rely on it for this scam. Recognizing the red flags is the real protection.
How do I explain this to less tech-savvy staff?
Keep it to one sentence: “If a ‘verify you’re human’ page ever tells you to press Windows + R, open Terminal, or paste something and hit Enter, close it and tell me.” That single rule covers nearly every version of this scam. You do not need anyone to understand the technical details, only to recognize the pattern and stop.

Worried about your practice’s online safety?

We build and manage secure, accessible websites for private practices, and we are happy to be a plain-language resource when something like this lands in your inbox. Reach out any time.

Get in touch with Transference Studio
·

Sources

This article is a plain-language summary of guidance and reporting from government and security sources, current as of June 2026. Security threats evolve quickly, so always follow the most recent official guidance.

  1. Federal Trade Commission. How to spot a CAPTCHA scam. Consumer Advice, June 2026. consumer.ftc.gov
  2. Federal Trade Commission. ReportFraud portal. reportfraud.ftc.gov
  3. The Hacker News. ClickFix Attacks Expand Using Fake CAPTCHAs. January 2026. thehackernews.com
  4. Evalian. ClickFix attack: how fake CAPTCHA and “fix” prompts deliver malware. April 2026. evalian.co.uk
  5. Identity Theft Resource Center, via reporting on response steps. 2026.
  6. York University Information Security. Fake CAPTCHA, Real Threat: ClickFix. April 2026. yorku.ca
  7. Techlicious. FTC warns: Fake CAPTCHAs are installing malware. June 2026. techlicious.com