A website asking you to run a Windows command to prove you're human is a reason to stop. Even if you arrived through a familiar service, that request puts your computer at risk.
In an October 1, 2026 report, Island traced Google ads through attacker-authored content on genuine ChatGPT pages. A fake service warning sent visitors to a supposed backup site, where a counterfeit verification asked them to run a Windows command that retrieved malware. The technique is called ClickFix.
Island recorded about 850 paid-ad landings across the broader cluster. Only a subset of destinations was confirmed to serve this exact lure. Those figures do not establish how many computers were infected.
The request matters more than the logo
A search result, a familiar chat interface and a security check can each feel routine. Together, they can make an unexpected instruction seem like the next step in getting work done.
The useful question is what the page wants you to do. Reading a response in your browser is one thing. Giving a command to your computer is a different action with different consequences. You don't need to understand the command to recognise that a human-verification check should never require it.
This is a practical addition to checking web addresses: assess the instruction as well as the page. A familiar name cannot make an unsafe request safe. Our guide to malvertising explains the wider problem of malicious advertising.
What ClickFix is asking you to do
Microsoft describes ClickFix as a technique that persuades people to execute malicious commands under the cover of a repair or verification. Instructions may mention Windows Run, Terminal or PowerShell, tools that can execute commands on your device. Delivered malware can include software that steals information or gives someone remote access.
Treat these requests as reasons to close the page:
- Open a command window to complete a CAPTCHA or human check.
- Paste text supplied by a webpage into a system tool.
- Disable security protection to finish verification.
Don't try the steps to see whether they work. Ask your IT team through a contact method you already know.
If you saw the prompt or already followed it
If you only saw the prompt: close the page and avoid its backup or repair links. For work tools, return through your organisation's approved app launcher or a saved, verified bookmark. Report the suspicious page through your usual security channel.
If you pasted and ran a command: stop using the device for work and contact IT or security immediately, using another device if possible. Follow your organisation's incident procedure. Tell the team roughly when it happened, which page you visited and what actions you took. Don't run the command again to reproduce the problem.
If you aren't sure whether the command ran, say so. That uncertainty helps the team decide what to investigate. A window disappearing quickly is not enough to tell you whether the device is safe.
Give employees a clear place to stop
For organisations, a useful training exercise is to show a fake verification and ask where the employee would pause. Include the reporting route in the exercise so that asking for help is as straightforward as recognising the warning sign.
Microsoft recommends combining user education with device policies, such as restricting access to Windows Run where employees don't need it. IT should assess those restrictions against actual work requirements.
Make the everyday instruction simple: if a website asks you to run a command for verification, stop and contact IT. Employees shouldn't have to analyse a script before deciding they can ask for help.




