A “CAPTCHA” told you to press Win + R. Here is what that was

A box that looks like a normal bot check asks you to press a few keys to prove you are human. Those keys run a command that installs password-stealing malware, on Windows and on Mac. Here is how to recognise it, and what to do in the next hour if you already followed the steps.

ByNikita Lushpanov· Chief Product Officer ·LinkedIn
Quick answer

No real CAPTCHA asks you to press Windows + R, open PowerShell or Terminal, or paste anything. A page that does is running the ClickFix scam: it has copied a malicious command to your clipboard and wants you to run it. Close the tab. If you already pressed Enter, disconnect from the internet, change your email and bank passwords from another device, sign out of all sessions, scan or reinstall the computer, and report the page at reportfraud.ftc.gov.

1. What you see on the screen

You open a page, sometimes one you have used for years, and a box appears in front of it. It looks like the usual bot check: a checkbox, the words “Verify you are human”, sometimes a Cloudflare or reCAPTCHA logo. You tick it, and instead of pictures of traffic lights you get “verification steps”: press Windows + R, press Ctrl + V, press Enter. On a Mac it is Cmd + Space, type Terminal, paste, Enter. Other versions show a fake browser error, a “missing font” or a broken video player with a “Fix it” button that leads to the same instructions. The page has already placed a command in your clipboard. You cannot see it, and the steps are written to keep it that way.

2. What those three keys actually do

Windows + R opens the Run box, a small window that executes whatever you type into it. Ctrl + V pastes the hidden command. Enter runs it with your permissions. That command typically reaches out to a server, pulls down a password stealer and starts it quietly in the background, often while showing a harmless “verification complete” message. The trick is that you ran it yourself. Browsers and antivirus tools are good at flagging a suspicious download, but a command typed into the system by the user looks, to much of that software, like something the user meant to do.

3. Why it spread so fast in September 2026

ClickFix has been around since 2024, but this autumn it reached the general public. Early in September BleepingComputer reported more than 5,400 hacked websites serving the fake CAPTCHA, which is why it turns up on pages people trust. On 14 September TechCrunch described the campaigns targeting both Windows and Mac users, and the same week the official HBO Max account on Reddit was taken over and used to post ads pointing to a fake login page with a ClickFix lure. The FTC had already published a consumer warning about CAPTCHA scams on 8 June 2026, and local TV stations spent the summer covering viewers who had followed the steps.

4. How to tell a real CAPTCHA from a fake one

A real CAPTCHA does its work inside the web page. It asks you to tick a box, pick pictures, type distorted letters or wait a second while it checks your browser. That is all. It never asks you to leave the browser, open the Run box, PowerShell, Command Prompt or Terminal, or paste anything anywhere. Once a page tells you to press a system shortcut, stop there. The same rule covers “fix this error” pop-ups, fake browser update pages and support chats that walk you through a command. If you want to know whether something on your computer needs fixing, open the settings yourself. Never take instructions from a page.

5. If you already ran the command

Speed matters, because a password stealer sends its haul within minutes. Disconnect the computer from the internet. On a different device, change the password to your main email first, since email is what resets everything else, then banking, then any account that was logged in on that computer. Sign out of all other sessions in each account, because stolen login cookies keep working after a password change until you do. Turn on two-factor authentication where it is missing. Then deal with the computer: a full scan with updated security software, or a wipe and reinstall if you want to be certain. Tell your bank if card details were saved in the browser, and move any crypto to a new wallet from a clean device.

6. What the stolen data is used for next

Stolen browser data is bundled into “logs” and sold, usually within days. Buyers use them to get into email, shopping and bank accounts, to reset passwords elsewhere and to run follow-up scams with your real name and address. Such logs do not always show up in public breach lists straight away, so a clean result on a breach check does not prove your passwords are safe after an infection. Change them anyway. It is still worth checking whether your email address appears in known breach databases, because old leaks tell you which passwords were already exposed before this, and which accounts to deal with first. Our guide to what to do after a data breach covers the order that limits the damage.

7. Reporting it, and protecting the people around you

Report the page at reportfraud.ftc.gov, and at ic3.gov if you lost money or accounts. If the fake check appeared on a site you know, tell the owner; the site itself has been hacked and is infecting every visitor. Then pass the one rule on to family members, especially older relatives and teenagers who install things quickly: a website never needs you to press Windows + R, open Terminal or paste a command. It is short enough to remember, and it covers every version of this scam, including the ones that have not appeared yet. Our guide to protecting elderly parents from scams has more rules of this kind.

Find out what was already exposed

After an infection it helps to know which of your accounts and passwords were already in known breaches, and which sites publish your address and phone number for the follow-up scams. PersProtect checks both. The scan is free.

Check my email for breaches — free →
Common questions

Fake CAPTCHA scams, answered

Why is a website asking me to press Windows + R to verify I am human?

Because it is not a real CAPTCHA. Windows + R opens the Run box, and the page has already copied a command to your clipboard, so Ctrl + V and Enter would run it. No genuine CAPTCHA, Cloudflare check or Google test ever asks you to open Run, PowerShell, Command Prompt or Terminal. Close the tab without pressing anything.

What is ClickFix?

ClickFix is the name security researchers use for attacks that get you to run the malicious command yourself. The page shows a fake “verify you are human” box or a fake error with a “fix it” button, copies a command to your clipboard and tells you which keys to press. Because you run it, much of the usual download protection never sees a file to check. In 2026 it became one of the most common ways to spread password-stealing malware.

Does the fake CAPTCHA scam work on a Mac?

Yes. On a Mac the page asks you to press Cmd + Space, open Terminal and paste a line. The command downloads a Mac password stealer instead of a Windows one. TechCrunch reported in September 2026 that the same campaigns now target both systems, so using a Mac is no protection if you paste the command.

I pressed the keys and hit Enter. What do I do first?

Disconnect the computer from the internet, by turning off Wi-Fi or pulling the cable. Then use a different device, such as your phone, to change the password for your email first, then your bank and any account you were logged into on that computer, and sign out all other sessions. After that, run a full scan with up-to-date security software on the affected machine, or have it wiped and reinstalled if you are unsure.

I only clicked the checkbox and closed the page. Am I infected?

Very likely not. Clicking the fake checkbox only copies a command to your clipboard; nothing runs until you paste it into Run, PowerShell or Terminal and press Enter. Copy some ordinary text to overwrite the clipboard, close the tab, and do not return to that site. If the site is one you trust, it has probably been hacked, so let the owner know.

What does the malware steal?

Mostly whatever your browser remembers: saved passwords, autofill data such as addresses and card numbers, the session cookies that keep you logged in, and crypto wallets. The stolen session cookies let attackers into accounts without a password or a two-factor code, which is why you need to sign out of every session as well as change the password.

Where do I report a fake CAPTCHA page?

Report it to the FTC at reportfraud.ftc.gov, which published its own warning about CAPTCHA scams in June 2026. If money or accounts were taken, also file with the FBI at ic3.gov and tell your bank. If the fake box appeared on a legitimate site, contact that site, because it has been compromised and is infecting other visitors.

Stolen passwords are only half of it

See which breaches your email is in and which sites publish your personal details — free, in about a minute.

Run my free exposure scan →