Need urgent help?

Call our team on 0207 099 0740

Need urgent help?
0207 099 0740
Client Portal
view of earth from space which shows some areas with lights on as it is night time

10 August 2026

2 minutes read time

The steep rise in ‘ClickFix’ style phishing attacks  

Author

As Chief Information Security Officer at CloudTech24, I lead security strategy, governance and operational delivery. I help our clients’ executive teams make informed decisions about cyber risk. My role involves understanding how a customer’s business actually works, where the real risks sit, and what it takes to reduce them in a way that lasts, using existing capabilities wherever possible.

My background spans hands-on technical delivery and board-level advisory to clients across fintech, financial services, legal and other regulated industries. I also own our ISO 27001 programme and the ISMS behind it. As AI moves into everyday business use, I also ensure that our usage of AI aligns to best practise through governance and policy, and advise leadership and customers on safe adoption, aligning toward emerging standards such as ISO 42001 and the EU AI Act.

Outside of work, I’m a proud dad to two brilliant daughters and a lifelong LEGO enthusiast – if we’ve had a video call, chances are you’ve seen a few of my builds in the background. I’m also a passionate gamer and PC builder, a hobby I picked up in the early 2000s with my dad, who first sparked my interest in computers. Fun fact: back in the day, I was Europe’s #1 ranked Battlefield 1942 player – proof that my competitive streak goes way back!

Read blogs in other categories

What is ClickFix?

ClickFix is a social engineering technique that the Security Operations team at CloudTech24 are seeing cybercriminals use to trick users into infecting their own devices.

Typically, we find that a user is redirected to a fake verification page that impersonates a trusted service such as Cloudflare, Google reCAPTCHA, or a website security check. The page claims the user must complete a verification step before accessing the website.

Unlike traditional phishing attacks, the page does not ask for credentials. Instead, it instructs the user to copy and paste a command into the Run dialogue box (Windows) or Terminal (macOS) and execute it. This command then downloads and runs malicious code directly on the user’s device.

These attacks are typically more successful due to these fake verification pages appearing on legitimate websites. The attackers will compromise a legitimate website that you may regularly use and then place the CAPTCHA/Verification.

What you should look out for

The images below are real-world examples of ClickFix style attacks:

ClickFix Mac image The steep rise in 'ClickFix' style phishing attacks  
iClicker fake captcha security incident Office of Information Technology 1 The steep rise in 'ClickFix' style phishing attacks  

The impact of an attack

A ClickFix campaign can result in:

  • Malware installation
  • Credential theft
  • Command-and-control (C2) activity
  • Unauthorised access to corporate systems
  • Theft of sensitive data.

In severe cases, it can provide attackers with persistent access to an environment and act as a precursor to ransomware or further compromise.

Recommended response

If a user encounters a ClickFix style prompt, our cybersecurity specialists advise the following:

  1. Do not copy or run any commands
  2. If you can, capture/screenshot the URL, then close the browser tab immediately
  3. Report the incident to your IT/Security team.

If you have already run the command:

  1. Disconnect the device from the network
  2. Contact CloudTech24 immediately
  3. Do not attempt to clean the device yourself
  4. Assume any credentials used on that device are compromised and change them from a different device.

Concerned about phishing attacks?

CloudTech24 clients are welcome to schedule a call with their Customer Success Manager to discuss phishing attacks. If you are interested in CloudTech24’s managed email security and/or Managed Detection and Response (MDR) services, contact CloudTech24 today. We can help you improve your cybersecurity and reduce risk.

Back to blog

Recent blogs from CT24

view of earth from space which shows some areas with lights on as it is night time

The steep rise in ‘ClickFix’ style phishing attacks  

What is ClickFix? ClickFix is a social engineering technique that the Security Operations team at CloudTech24 are seeing cybercriminals use to trick users into infecting their own devices. Typically, we find that a user is redirected to a fake verification page that impersonates a trusted service such as Cloudflare, Google reCAPTCHA, or a website security…

Read more

What is a virtual CISO (vCISO)?

Cybersecurity issues don’t pop up one at a time. They’re often frequent, urgent, and complex. When issues build up and the level of complexity increases to the point where your team needs an extra hand, having a vCISO can lighten the load. A vCISO (Virtual Chief Information Security Officer) is a security leader who serves…

Read more

Which one is better – AWS, Azure, or Google Cloud?

Choosing the right cloud infrastructure is a decision you can’t take lightly. Today, businesses must decide whether to build their applications on AWS, Azure, or Google Cloud. While these platforms offer similar core features like storage and computing power, each vendor approaches infrastructure, security, and developer experience with a completely different philosophy. This blog breaks…

Read more