...
Facet Technologies home

(309) 689-3900

Call our office!

3024 W. Lake Ave., Suite 1

Peoria, IL 61615

8:00AM - 5:00PM

Monday – Friday

Facet Blog

Cyber Treats: ClickFix Attacks

March 19, 2026

Ellie Shaw

Ellie Shaw

Ellie Shaw is the Director of Marketing at Facet and the author of Cyber Treats, Facet's biweekly newsletter featuring topics like IT news, cybersecurity updates, compliance advice, and anything tech. She has been a member of the Facet team full-time since 2016 and enjoys finding new ways to share resources and information about cybersecurity with others.

Want more Cyber Treats? 👉 https://facettech.com/cybertreats/

Our next AI Fluent Leaders webinar is coming up next Wednesday, March 25. We’re going live with Copilot: real prompts, real demos, real tricks you can use the same day. More details at the bottom of this newsletter. Register here!

We first wrote about ClickFix in August. Since then, ClickFix has become responsible for 47% of initial access incidents in 2025 according to Microsoft, and a large ransomware group called LeakNet adopted it just this week. This newsletter includes updated details on the growing threat.

What’s a ClickFix Attack?

Ransomware doesn’t necessarily arrive in your inbox disguised as a fake invoice or urgent payment request.

This threat lurks on legitimate websites that have been secretly compromised, in emails with fake “Captcha” pages, or through online ads that look like the real thing. It keeps evolving, with a new variant discovered this month that actually bypassed endpoint detection programs.

How a ClickFix Scheme Strikes

The Setup: Criminals hack legitimate websites or create “lookalike” sites and plant invisible code.

The Hook: You visit a trusted site. A popup appears: usually a fake Cloudflare CAPTCHA, a “browser critical error,” or a “security update required” message. Behind the scenes, malicious code is silently copied to your clipboard.

The Trap: The fake message instructs you to press Windows key + R, press Ctrl + V, and press Enter. These three keystrokes execute hidden malicious code, instantly infecting your system. Because you ran the command, many security tools don’t flag it as suspicious.

Real-World Examples of ClickFix Pop-Up Messages

”Verify You Are Human” CAPTCHA checks on compromised websites

“Browser Critical Error” messages on familiar websites

“Update Required Immediately” popups with manual instructions

“Fix Network Connection” prompts asking you to copy/paste commands

“Security Alert” windows requesting keyboard shortcuts instead of normal downloads

Six Guidelines to Prevent ClickFix Attacks

  • Never follow keyboard instructions from popups. No legitimate website will ever ask you to open the Windows Run dialog
  • Close suspicious windows immediately
  • Update browsers through official channels only
  • When in doubt, restart your browser
  • Report suspicious sites to your IT provider
  • Put preventative measures in place including MFA, firewalls, and email filtering according to CISA’s guidelines (our team can manage this process for you)

ClickFix has grown from an emerging threat to one of the most effective attack methods in use today because it turns the user into the delivery mechanism. Your best protection is skepticism. No real security update, CAPTCHA, or error fix requires you to open the Run dialog and paste a command.

Need guidance with training employees or exploring advanced security options? Call us at (309) 689-3900 to request a consultation.

AI Fluent Leaders: Session 3

Practical AI You Already Own: Microsoft Copilot in the Real World

If you’ve been using ChatGPT, Gemini, or any other AI tool at work, you already know AI is useful. Now imagine that same kind of help, except it can read your emails, recap your meetings, and pull from your actual company files. That’s what Microsoft Copilot does, and your organization might already have access to it (don’t worry, we’ll show you how to make the switch seamless).

We’re going live to show you the prompts and tricks that make Copilot worth using every day: “type this, get this” demos you can try the minute you get back to your desk. You’ll walk away with a free cheat sheet of ready-to-use prompts.

Register for the Webinar Now

Missed the first AI-Fluent Leaders sessions?

No problem—you can catch the recordings here: Watch AI Fluent Leaders Sessions 1 and 2.

Want more Cyber Treats? 👉 https://facettech.com/cybertreats/

Ellie Shaw is the Director of Marketing at Facet and the author of Cyber Treats, Facet's biweekly newsletter featuring topics like IT news, cybersecurity updates, compliance advice, and anything tech. She has been a member of the Facet team full-time since 2016 and enjoys finding new ways to share resources and information about cybersecurity with others.

Share this post