In mid-2026 reports of an attack technique called ClickFix are piling up. The Swiss National Cyber Security Centre (BACS) warned in late September about attacks using fake error messages that have been increasing for several weeks. A security vendor reported in May that over 700 education and technology websites had been hijacked to run such a campaign.
The scam
The victim visits a compromised website. A fake message appears: an alleged technical problem, an "I am not a robot" check or an update. To "fix" it, the user is told to copy a command and paste it into the Windows Run dialog or PowerShell. By doing so, they launch the malware themselves.
Why it works
The attack needs no vulnerability. It exploits helpfulness and routine: people who click away error messages all day will also follow instructions. Because the user runs the command themselves, some browser and operating-system protections never trigger.
A website that asks you to paste a command into a system window is always an attack.
Defence: technology and training
- Technology: restrict the Run dialog and PowerShell for regular users by policy (e.g. AppLocker/WDAC, Constrained Language Mode)
- Detection: EDR rules for browser-adjacent child processes and suspicious command lines
- Training: teach one clear rule — never run commands from a web page
- Testing: verify with an agreed, authorised simulation that policies and detection actually work
BACS also recommends installing only needed apps and extensions, keeping devices up to date and not following every prompt.
Conclusion
ClickFix shows that no patch helps against attacks without a vulnerability. You need technical barriers that catch individual mistakes, and a simple rule everyone remembers.