One of our client's team members did something millions of people do every day — looked up a supplier's website and clicked through an "are you a robot?" check. This one was fake, and it quietly ran malware built to steal passwords and hijack live logins. Within minutes, our 24×7 threat hunting had spotted it and cut the machine off the network — turning what could have been a serious breach into a contained, no-drama incident.
There was nothing reckless about it. A staff member searched for a company they deal with, opened what looked like the right website, and was met with a familiar "verify you're human" prompt.
This is a fast-growing style of attack the industry calls ClickFix, or the "fake CAPTCHA." Instead of ticking a box, the page calmly instructs you to press a short sequence of keys as a "verification step." Follow along, and you've unknowingly pasted and run a hidden command on your own computer — no dodgy download, no obvious warning. It preys on the exact habit we've all been trained into: clicking through CAPTCHAs without a second thought.
The attack and our response, step by step. It plays automatically — or hit replay.
What makes this technique nasty isn't just the trick — it's how well it slips past traditional defences.
"You can train people all day, but eventually someone, somewhere, will click. Good security assumes that — and is ready to catch it when it happens."
This is exactly the moment layered cybersecurity earns its keep. No single tool saved the day; the layers did — working together, around the clock.
"Antivirus alone would have missed this. It was the layers — 24×7 threat hunting, behavioural detection and instant isolation — that turned a potential disaster into a contained incident."
If your cybersecurity is really just antivirus and hope, an attack like this walks straight in. Book a free IT Health Check and we'll show you, honestly, where you'd stand — and what layered protection actually looks like.