A fake CAPTCHA scam looks like a normal “verify you are human” page, but it may try to make you copy, paste, or run a command outside your browser. A real CAPTCHA stays inside the webpage. If a verification page asks you to open PowerShell, Command Prompt, Terminal, Run, or install something, close the tab and do not continue.

The simple rule

#

Here is the easiest way to remember it:

A real CAPTCHA checks you inside the browser. A fake CAPTCHA tries to make you do something outside the browser.

That one rule catches most ClickFix-style scams.

If you see instructions involving PowerShell, Command Prompt, Terminal, the Run box, copied text, “manual verification,” or “fix your browser,” treat the page as unsafe.

You do not need to understand what the command does. You just need to know that a real CAPTCHA would not ask for it.

Why these scams work

#

Most of us have been trained to move through CAPTCHAs quickly.

You see “verify you are human,” you click, you wait, and you move on. It feels normal because we have done it hundreds of times.

Scammers take advantage of that habit.

A ClickFix scam may copy the look of a familiar verification page. It may use trusted-looking logos, clean design, and official-sounding language.

At first, nothing feels very suspicious.

Then comes the trick.

The page tells you there is a problem with your browser, your verification failed, or you need to complete a “manual” step. It may ask you to copy something and paste it into a tool on your computer.

That is not verification. That is social engineering.

Instead of hacking your device directly, the scam tries to convince you to do the dangerous part yourself.

Security researchers and consumer-protection agencies have warned about fake CAPTCHA and ClickFix attacks because they are easy to fall for. They do not always rely on a normal download button. Sometimes the entire scam is built around making a harmful command look like a harmless verification step.

Real CAPTCHA vs fake CAPTCHA

#

Red flags to watch for

#

One red flag is enough to stop.

Be careful if a “verify you are human” page:

  • Tells you to copy something
  • Tells you to paste something
  • Mentions PowerShell, Command Prompt, Terminal, or Run
  • Says your browser needs to be fixed
  • Says verification must be completed manually
  • Gives step-by-step keyboard shortcuts
  • Uses urgent language like “continue now” or “verification failed”
  • Appears after clicking an ad, pop-up, shortened link, file-sharing page, or suspicious download page
  • Looks official, but the instructions feel strange

Trust the behavior, not the logo.

A scam page can copy the design of a real company. It can use familiar colors and names. But a real CAPTCHA does not need access to your computer’s command tools.

Safe checklist before you click, copy, or paste

#

Use this checklist whenever a verification page feels unusual.

1. Pause for a few seconds

#

Scams work best when you are rushing.

Before doing anything, slow down and read the instructions.

Ask yourself:

“Is this still happening inside the webpage, or is it asking me to use my computer?”

If the page wants you to leave the browser, stop.

2. Do not click a “copy” button

#

Fake CAPTCHA pages often include a copy button.

The text may look harmless. You may not even see the full thing. In some cases, the page may copy something technical to your clipboard without making it clear.

Do not copy it.

And if you already copied it, do not paste it into PowerShell, Terminal, Command Prompt, the Run box, a document, a chat app, or anywhere else.

3. Do not open system tools for a CAPTCHA

#

A website does not need system-level tools to prove you are human.

Not PowerShell. Not Command Prompt. Not Terminal. Not the Run box. Not any “admin” tool.

If a page says that is required, it is not acting like a normal CAPTCHA.

Close the tab.

4. Do not trust the page just because it looks familiar

#

Scammers can copy logos and layouts.

A fake page may look like Google, Cloudflare, your browser, your operating system, or a security product. That does not make it safe.

Instead of asking, “Does this look real?” ask:

“Would a real CAPTCHA ask me to do this?”

If the answer is no, leave.

5. Close the tab if something feels wrong

#

You do not owe the page another click.

Close the tab or browser window. If it tries to stop you from leaving, use your browser’s normal close controls or restart the browser.

Avoid clicking extra buttons on the suspicious page, even if they say things like “cancel,” “continue,” “fix,” or “try again.”

6. Clear your clipboard if you copied something

#

If you clicked a copy button but did not paste or run anything, the risk is usually much lower.

Still, clear your clipboard.

An easy way to do that is to copy a harmless word or sentence from somewhere safe, such as a note you write yourself. That replaces whatever the scam page placed on your clipboard.

7. Reopen the site from a trusted place

#

If you were trying to visit a real website, do not go back through the same link.

Avoid the same ad, pop-up, email, message, search result, or download page that led you there.

Instead:

  • Type the address yourself
  • Use a saved bookmark
  • Open the official app
  • Search carefully and choose the official site

8. Keep your browser and device updated

#

Updates do not stop every scam, but they reduce your risk.

Use official update settings on your device and browser. Do not trust random website pop-ups that claim your browser, video player, antivirus, or system software is out of date.

Fake update messages are another common trick.

What to do if you already ran a command

#

First, take a breath.

These scams are designed to make normal people act quickly. If you followed the instructions, you are not the first person to be tricked by this.

What matters now is limiting the damage.

If you pasted something into PowerShell, Command Prompt, Terminal, the Run box, or another system tool and ran it, treat the device as potentially compromised.

1. Disconnect from the internet

#

Turn off Wi-Fi or unplug the network cable.

This does not clean the device, but it may stop malware from communicating with someone else while you take the next steps.

2. Do not enter more passwords on that device

#

Avoid logging into important accounts from the affected device.

That includes email, banking, payment apps, work or school accounts, social media, shopping accounts, creator platforms, crypto wallets, and password managers.

If malware is active, typing more passwords could make things worse.

3. Use another trusted device for account recovery

#

Use a phone, tablet, or computer that was not involved in the scam.

From that safer device:

  • Change your main email password first
  • Change passwords for banking, payments, shopping, work, school, and social accounts
  • Change your password manager password if you use one
  • Turn on multi-factor authentication where available
  • Sign out of other sessions if the service offers that option
  • Review recent account activity

Use official websites or apps only. Do not use links from the suspicious page.

4. Run a full malware scan

#

Use trusted security software or the built-in security tools from your operating system.

If this is a work or school device, contact your IT team before making major changes. They may need to inspect the device, remove it from the network, or reset it.

A scan is important, but no scan can guarantee perfect certainty in every situation. If sensitive data, money, or work access is involved, get help quickly.

5. Contact official support if money or accounts may be at risk

#

If you use the device for banking, payments, business tools, creator income, crypto, or important accounts, contact the official support channel.

For example:

  • Call your bank using the number on your card or the official website
  • Contact payment apps through their official app or site
  • Report suspicious activity to your email or social media provider
  • Notify your workplace or school IT department
  • Review recent transactions and account logins

Do not be embarrassed. Fast reporting can reduce the damage.

6. Watch for follow-up scams

#

After one scam attempt, you may see more.

Be suspicious of emails, texts, calls, or pop-ups claiming:

  • Your device has been hacked
  • Your account is locked
  • You need to pay to remove malware
  • A support agent needs remote access
  • You must install a security update
  • Your bank or email account needs urgent verification

Go directly to official support pages. Do not trust links or phone numbers sent in suspicious messages.

What if this happens on a phone?

#

Many ClickFix scams target desktop users, especially Windows and Mac users. But fake CAPTCHA pages can appear on phones too.

On a phone, the scam may ask you to install an app, change settings, allow permissions, or copy instructions into another app.

The rule is the same:

Verification should not require installing apps, changing settings, or pasting technical instructions.

If you see a suspicious CAPTCHA page on your phone:

  • Do not install anything from the page
  • Do not copy and paste instructions
  • Do not grant unusual permissions
  • Close the tab
  • Clear browser history if the page keeps coming back
  • Update your phone and browser through official settings
  • Remove anything you installed from the page
  • Use official device security guidance if you are unsure

A simple rule to share with family

#

If you help parents, grandparents, kids, students, or coworkers, give them this sentence:

“A real CAPTCHA never asks you to paste anything into your computer.”

It is short, easy to remember, and catches the main danger.

You can also say:

“If a website asks you to open PowerShell, Command Prompt, Terminal, or Run, close the page and ask for help.”

That advice can prevent a lot of damage.

Final takeaway

#

A CAPTCHA should be boring.

Click a box. Pick some images. Wait a moment. Continue.

The moment a verification page asks you to copy, paste, run commands, open system tools, install something, or “fix” your browser, it is no longer acting like a normal CAPTCHA.

Close the tab.

And remember the simplest rule:

A real CAPTCHA never asks you to paste anything into your computer.