CCIT News and Notices

ClickFix surpasses phishing as most common scam

The ClickFix scam, also called the Copy to Fix scam, has become the primary technique used by cybercriminals, even surpassing conventional phishing emails. The scam is a social engineering attack that tricks users into pasting harmful code into their computer.

The scam may appear as a pop-up on a webpage, in a Word document, or when you open a PDF. It claims there’s a problem and offers a button labeled “How to Fix,” “Auto-Fix,” or something similar.

If you follow the instructions, the button may secretly copy harmful code to your computer’s clipboard. The page then walks you through opening a system tool, like the Run dialog on Windows or Terminal on a Mac, and pasting and running the code. Once run, the code can download malware and lead to other harmful activities.

Because you copy and paste the code yourself, antivirus software may not detect it before it runs.

If you see this kind of pop-up, don’t follow its instructions. Contact your area’s IT Consultant for help. Legitimate security checks and error fixes will never ask you to run system commands manually.

Screenshot of the ClickFix scam pop-up window, reading "There was an error during the latest update of browser version, follow these instructions to continue." The instructions detail how to copy the fix and paste into Windows PowerShell, which will install malware on your computer.