ClickFix attacks are tricking Mac and Windows users into hacking themselves

https://techcrunch.com/wp-content/uploads/2026/09/hbo-max-screenshot-clickfix.jpg?resize=1200,843

If you clicked on an HBO Max ad on Reddit over the past week, you might want to check your computer for malware.

These so-called “ClickFix” attacks have quickly become one of the rising cybersecurity threats of 2026, and they’re getting both sneakier and compromising people’s devices with greater frequency. Until recently, ClickFix attacks were a rarity, capitalizing on people searching the web for quick tech fixes. They have since evolved into a massive international effort to hack into people’s computers.

The attacks involve fake websites, or legitimate websites that have been hacked, which display a message that appears to look like a CAPTCHA or an anti-bot checkbox. Once clicked, a prompt appears asking the user to perform a “check” to proceed, which gives instructions to copy and paste a string of text into the user’s Windows command prompt or Mac Terminal app.

As soon as the user hits return,...

Copyright of this story solely belongs to techcrunch.com. To see the full text click HERE

Read more