Blog · Phishing · 9 October 2026 · 2 min read
“Press Win+R and paste”: a fake CAPTCHA has already infected thousands of small-business websites
Netskope found more than 5,400 hacked websites, mostly of small businesses, showing visitors a fake verification. What to do as a user, and how to check your own site isn't one of them.
You visit the website of a clinic, a plumber or an online shop. The familiar "Confirm you're not a robot" box appears. Only instead of ticking a box, you're told to do three things: press Windows + R, then Ctrl + V, then Enter.
At that moment you install the malware yourself. The page quietly copied a command to your clipboard that downloads and runs the attackers' program. The technique is called ClickFix.
The scale in September 2026
- Netskope Threat Labs (September 2026) found more than 5,400 hacked websites belonging to more than 2,200 organisations. What they had in common: most were small-business sites, and among those examined WordPress dominated, with some on PrestaShop.
- According to Push Security data, ClickFix made up 67% of the browser attacks they detected in August 2026.
- Variants also pose as a full-screen Windows update or a "browser repair". Both Windows and macOS are targeted (on a Mac you're told to paste a command into Terminal).
The rule for every employee
No legitimate website ever asks you to paste anything into the Run box, PowerShell or Terminal. Never. Not a CAPTCHA, not Google, not Microsoft, not your bank.
If you already did it:
- Disconnect the computer from the internet (unplug the cable, turn off Wi-Fi).
- From another device, change your e-mail password first, then your bank and other important accounts.
- Sign out of all active sessions (Microsoft 365, Google, bank).
- Scan the computer with antivirus, or better, hand it to your IT person.
What if it's your site scaring customers?
The owner usually finds out last, because they visit the site logged in as an administrator, and the malicious script only shows up for new visitors. Check:
- Open the site in a private window on a phone with Wi-Fi turned off (a different IP address). Is there a verification you've never seen before?
- Update WordPress, your theme and plugins, and delete plugins you don't use. In July and September 2026 the US agency CISA added three vulnerabilities in WordPress core itself to its list of actively exploited ones.
- Change administrator passwords and turn on two-factor login.
- Ask your host to scan the files, or restore a backup from before the infection.
In short
- A CAPTCHA that tells you to press Win+R is an attack. Close the tab.
- Pasted the command? Disconnect from the internet and change passwords from another device.
- Your own site may be handing out this attack without you knowing. Check it from someone else's device and update it.
Sources: Fox News / CyberGuy, 13 Sep 2026, Netskope report, Push Security, TechCrunch, 14 Sep 2026.