Overview
Fake verification or CAPTCHA scams use a realistic-looking web page to persuade you to run a command on your own computer. The page may claim that you must prove you are human, fix a browser problem, view a document, restore access, or complete a security check.
These attacks are sometimes associated with names such as ClearFake or ClickFix. The name is less important than the behavior: the page tells you to open a system tool and paste or execute instructions that can install malicious software.
Copying a command from a website is not always malicious. Technical documentation may legitimately provide commands for administrators, developers, researchers, or other users who understand the task and trust the source. However, a legitimate CAPTCHA, human-verification step, or browser security check does not require you to open Run, Command Prompt, PowerShell, Terminal, or another command-line tool and paste or execute a command.
How It Works
A common attack follows this pattern:
- You reach a deceptive page. The page may open from an email, Teams or chat message, search result, advertisement, compromised website, document-sharing notice, or redirect.
- The page displays a fake verification or error prompt. It may resemble a CAPTCHA, browser update, security alert, document preview, or “fix” procedure.
- The page provides unusual instructions. It may tell you to press a keyboard shortcut such as Windows key + R, open Command Prompt or PowerShell, launch Terminal, paste clipboard contents, and press Enter or Return.
- The command runs with your permission. The pasted text may download and start malware, change security settings, steal information, or establish remote access.
- The page may appear to continue normally. A successful verification message or redirect can make it seem as though nothing harmful happened.
The page may place the command on the clipboard automatically. You may not see or understand what will be pasted before it runs. The attacker relies on you treating the steps as routine rather than as software execution.
Example of a Fake “Verification” Screen
The screen below may look legitimate, but any website that asks you to open system tools or paste commands is attempting to compromise your device.

Warning Signs
Stop when a verification, security, document, or browser page tells you to:
- Press Windows key + R or another shortcut to open the Run dialog.
- Open Command Prompt, PowerShell, Windows Terminal, Terminal, a shell, or a scripting tool.
- Paste clipboard contents into a system window and press Enter or Return.
- Copy and run a command to prove you are human, continue to a website, unlock a document, or fix a browser.
- Disable antivirus, browser protection, application controls, or another security feature.
- Ignore a security warning because the command is supposedly required for verification.
- Repeat the steps when the page does not appear to work.
- Call a phone number or contact “support” shown only in the warning page.
A real CAPTCHA may ask you to select images, enter characters, move a puzzle piece, check a box, or complete another task inside the webpage. It should not require you to leave the browser and execute a command on the computer.
How to Protect Yourself
- Do not follow the command instructions. Do not open Run, Command Prompt, PowerShell, Terminal, or another system tool for a verification prompt.
- Close the browser tab or window. If the page will not close normally, use the operating system's normal application controls or restart the device. Do not call a number displayed on the page.
- Do not paste unknown clipboard contents. The clipboard may contain a command placed there by the page.
- Verify the original message or website. Return to the known service through its official application or a trusted bookmark rather than reopening the suspicious link.
- Use caution with technical commands from websites. For legitimate technical work, confirm the source, understand what the command does, and follow approved procedures before running it.
- Keep the browser, operating system, and security software updated. Updates and security protections can reduce the chance that malicious content succeeds.
- Do not disable security controls at a page's request. A website should not require you to weaken the device to view ordinary content or complete a CAPTCHA.
- Report the source. Report the message, advertisement, account, or website through the relevant service when possible.
Merely seeing the page does not necessarily mean the device is compromised. The greatest concern is whether you pasted or ran a command, installed software, entered credentials, approved MFA, or granted another form of access.
What You Should Do at UM
If you see a fake verification or CAPTCHA page on a UM device, or after opening a link from a UM email, Teams message, or other university service:
- Do not follow the instructions or run a command.
- Close the tab or browser window.
- Contact the UM IT Helpdesk or UM Information Security Office and provide the message, website address, screenshot, or other details when doing so is safe.
- Report the original message through the appropriate service. For a suspected phishing email in Outlook, use the Report Message tool and report it as phishing. Delete the message after reporting it. The Report Message tool may remove it automatically.
If you pasted or ran a command, installed software, or allowed remote access on a UM device:
- Stop using the device for email, banking, password changes, or university work.
- Disconnect it from the network if unfamiliar activity is continuing or someone appears to have remote control.
- Contact the UM IT Helpdesk or UM Information Security Office immediately from another device. State clearly that you followed a fake CAPTCHA, verification, or browser-fix prompt and describe each step you completed.
- Do not erase, reset, or attempt to clean the device unless UM support directs you to do so.
If you entered your UM password, shared an MFA code, or approved an unexpected MFA request, change your UM password through the normal UM account-management process from a trusted device and contact UM support.
For a personal device that does not involve UM, stop sensitive activity and use the device manufacturer's, operating-system provider's, security provider's, or another trusted technical-support process. Secure potentially exposed accounts from a separate trusted device. Contact a financial institution immediately if financial information or money was involved.
Additional Questions
For a fake verification prompt involving a UM device, UM account, UM email or Teams message, or university information, contact the UM IT Helpdesk and the UM Information Security Office.
For a personal device or account:
- Contact the device manufacturer, operating-system provider, internet service provider, security-software provider, or another trusted technical-support service through an independently verified channel.
- Report the originating email, message, advertisement, or account to the relevant email, messaging, social-media, or advertising provider.
- Contact the relevant account provider if credentials, MFA, or account-recovery information may have been exposed.
- Contact your bank, credit union, card issuer, or payment provider immediately if financial information or transactions were involved.
Additional Resources