Most employees know the basics of phishing: don’t click suspicious links, don’t open unexpected attachments, and be cautious with unfamiliar emails.

But one of the fastest-growing cyber threats in 2026 is designed to bypass those instincts entirely.

Fake CAPTCHA attacks, commonly known as ClickFix, turn a familiar “I’m not a robot” verification into the attack itself. Instead of asking someone to download a file, the fake verification page instructs the user to press Windows + R, paste a command, and run it.

That simple action can give an attacker the foothold they need.

This Month’s Watchdog Warning: Fake CAPTCHA Attacks

CAPTCHAs have become so common online that most of us barely think about them. We click a box, identify a few traffic lights, or follow a verification prompt and move on.

Attackers are taking advantage of that familiarity.

With ClickFix, a compromised or malicious website displays what appears to be a legitimate verification step. The visitor is then instructed to copy and paste a command into the Windows Run box. By following those instructions, the employee can unknowingly execute malicious code themselves.

There may be no traditional attachment or obvious malicious download to warn them. The social engineering is the attack.

The technique is also becoming easier for criminals to deploy. ClickFix-style attack kits are being packaged and sold as a service, lowering the technical barrier for attackers. New variations—including fake system crash messages and methods using File Explorer—show how quickly the tactic is evolving.

Why We’re at Threat Level 4: High

Three factors make this month’s threat particularly concerning:

1. It relies on human behavior.

Employees are accustomed to following CAPTCHA and verification instructions, making the request feel more legitimate than a typical phishing email.

2. Attackers are moving quickly.

New variations continue to appear, giving cybercriminals different ways to use the same basic social-engineering technique.

3. Traditional security alone isn’t enough.

Endpoint protection, email filtering, DNS/web filtering, and other security controls remain important, but organizations also need employees who recognize when a “verification” request is actually asking them to execute something dangerous.

What We’re Hearing: Awareness Is the Problem

Most cybersecurity awareness training focuses heavily on suspicious links, attachments, passwords, and phishing emails.

That’s still important—but employees also need to understand newer attack methods.

Very few people recognize the terms ClickFix or fake CAPTCHA attack. And because legitimate CAPTCHAs are everywhere, an employee may not immediately question a page telling them they need to complete an extra step to prove they’re human.

That familiarity is exactly what attackers are exploiting.

Ears Up: Teach One Simple Rule

This month, Bent Ear recommends teaching every employee one rule:

No legitimate CAPTCHA or verification process should ask you to press Windows + R and paste or run a command.

If a website asks you to copy, paste, or execute something on your computer to “verify” that you’re human, stop and report it to IT.

It’s a simple awareness update that costs nothing to implement and can immediately reduce risk.

Organizations can reinforce that training with technical controls, including monitoring or restricting the use of tools such as PowerShell and the Windows Run command where appropriate, as well as DNS and web filtering designed to block known malicious or compromised sites.

Cyber Health Check

Ask your team:

If an employee saw a “prove you’re human” popup asking them to paste something into a Run box, would they know to stop and report it—or would they simply follow the instructions?

If you’re unsure of the answer, that’s a training gap worth addressing now.

Mike’s Take

“Fake CAPTCHA attacks work because they hijack trust in something we’re all trained to click through without thinking. The fix isn’t more software—it’s teaching your team that if a security check ever asks you to ‘run this to verify,’ that’s not verification. That’s the attack.”

The Myth: “I Don’t Click Suspicious Links, So I’m Safe.”

Avoiding suspicious links is still a good habit. But modern social engineering is evolving beyond the traditional phishing playbook.

Fake CAPTCHA attacks demonstrate why cybersecurity awareness needs to evolve with it.

The attacker doesn’t always need you to download something. Sometimes, they just need to convince you to run it yourself.

How Exposed Is Your Business?

Cybersecurity isn’t only about whether you have antivirus or a firewall. It’s about how your people, devices, policies, and security controls work together when an attack actually reaches them.

Bent Ear’s Cyber Risk Score Assessment can help identify gaps across your current cybersecurity posture and give your business a clearer picture of where risk may be hiding.

Take the Cyber Risk Score Assessment and find out where your business stands before an attacker tests it for you.