The Fake 'Fix' That Tricks You Into Hacking Yourself
Cybersecurity researchers at CrowdStrike are warning businesses about a growing attack technique called ClickFix, which turns employees into unwitting accomplices in their own compromise. Rather than tricking someone into opening a suspicious attachment, attackers present a fake error message, perhaps claiming a video meeting app needs repair, a browser needs verification, or a CAPTCHA needs completing. The 'fix' involves copying a command and pasting it into a trusted tool like the Windows Run dialog or PowerShell.
Once pasted and run, that command can launch further malicious activity, including downloading malware, stealing credentials, establishing persistent access, or connecting to attacker-controlled servers. CrowdStrike Intelligence has observed known threat groups using this method in real attacks, and its 2026 Global Threat Report recorded a 563% increase in incidents involving fake CAPTCHA lures during 2025.
What makes ClickFix particularly dangerous is that it exploits human instinct rather than a technical flaw, meaning it cannot simply be patched. Because the victim performs the final, harmful action themselves, traditional defences that look for suspicious attachments or links may not catch it in time.