Learn

The fake “verify you’re human” scam

A trick called “ClickFix” is spreading fast. A website shows what looks like a normal “verify you’re human” box, then asks you to press a few keys to continue. Those keys quietly run a hidden command that installs malware — and you did it yourself. Here is how it works and how to stay safe, in plain terms.

Key takeaways

  • A real CAPTCHA never asks you to leave your browser or type a command — it is just a click or a small puzzle inside the page.
  • The scam, nicknamed “ClickFix,” copies the familiar “verify you’re human” look to earn your trust, then gives you steps that secretly run malware.
  • It works because you run the command yourself, so it can slip past antivirus that would normally block a downloaded file.
  • The malware is usually an infostealer that copies saved passwords and account details from your computer.
  • The fix is simple: if any “verification” asks you to press keys, paste text, or open a system window, close the page.

What this scam looks like

You visit a website — sometimes a normal one that has been hacked — and a box appears that looks like the usual “verify you’re human” check. Instead of a simple checkbox, it says the verification “didn’t work” and gives you steps to fix it: press one key combination, then another, then Enter. It may add arrows or a countdown to make you hurry.

Security researchers call this trick “ClickFix.” It was first described in 2024 and has spread quickly since, and in 2026 the U.S. Federal Trade Commission warned that fake CAPTCHA pages were telling people to run hidden commands that could install malware.

Why it is clever

A normal CAPTCHA runs inside the web page. It never needs you to open anything on your computer. This scam relies on habit: people are so used to clicking through verification boxes that they follow the steps without stopping to think.

Because you run the command yourself, there is no risky file to download and no attachment to scan — which is why it can slip past security tools that would normally catch malware. In effect, the trick turns your own trust into the way in.

What the malware does

The hidden command usually installs an “infostealer” — software that quietly copies saved passwords, browser sign-in cookies, and other account details, then sends them to criminals. From there they may try to get into your email, bank, or social accounts.

This mostly targets computers — Windows most of all, and increasingly Mac — so it matters most when you are browsing on a laptop or desktop rather than a phone.

How to stay safe

Treat any “verification” that asks you to press keys, paste text, or open a system window as a scam, and close the page. A genuine check is only ever a click or a puzzle inside the page — nothing more.

Never paste a command you did not write yourself, even if a website promises it will “fix” something. Keep your computer and browser updated. If you think you ran one of these commands, change your important passwords from a device you trust and turn on two-factor login.

Where Sealby fits in

Sealby keeps your private photos, notes, and files in a vault encrypted with AES-256 on your iPhone, unlocked only by you. It cannot stop a scam on your computer, and it does not claim to.

What it shares with good scam sense is a simple idea: be cautious about any step that asks you to run a command or hand over access, and keep what matters most behind a lock only you control.

This is general education, not security advice. Scam tactics and wording change over time and differ by device and website — check current, reputable sources and treat any unexpected instruction with caution.

Quick answers

Is this the same as a normal CAPTCHA?

No. A real CAPTCHA is a click or a small puzzle inside the web page. If it asks you to press keys on your keyboard, paste text, or open something on your computer, it is a scam — not a verification step.

Does it affect iPhones?

The command trick mainly targets computers — Windows most of all, and increasingly Mac. Phones are a smaller target for this particular scam, but the habit it exploits — trusting a familiar box — is worth keeping in mind on any device.

What if I already followed the steps?

Assume passwords saved on that computer may be exposed. From a device you trust, change your important passwords and turn on two-factor login. Then run a security scan on the affected computer, or ask someone who can help.

How can a normal-looking website show this?

Criminals break into ordinary websites and add the fake box, so it can appear on sites you have used before. Seeing it on a familiar site does not mean the trick is safe to follow.

Your vault is waiting.

Download Sealby and protect what matters. Setup takes under a minute, and there’s no account to create.

Download on the App Store

iPhone & iPad · iOS 17+ · Free