Notice what the page asks you to do
The FTC’s June 2026 alert describes fake human-verification prompts that instruct visitors to paste and run commands on their computers. Its central distinction is simple: a legitimate CAPTCHA does not require device commands. Do not follow that request merely because the page calls it a security check. [1]
- A familiar-looking verification appears
- It asks you to run a device command
- Stop before pasting or executing
A familiar logo can hide a different action
Microsoft’s August 28, 2026 TerminalFix report describes compromised websites showing a counterfeit verification overlay. Interacting with it copied a malicious command to the clipboard; the instructions then directed visitors to paste it into a terminal. The command displayed reassuring status messages while starting the attack. This is Microsoft’s reported campaign, not evidence that every verification prompt is malicious. [2]
If you already followed the instructions
The FTC advises disconnecting from the internet, running a security scan and, from a different device, changing passwords and enabling two-factor authentication when malware may have been installed. Its linked guidance provides the fuller recovery steps. Closing the web page alone should not be treated as proof of recovery. [1]
Go a little deeper
Optional reading · about 1 more minute
The trust decision moved outside the page
Our interpretation: The important boundary is the change from interacting with a website to executing instructions on the computer. Judging only the logo or the reassuring wording misses that change. An instruction can be dangerous even when it is presented as the cure for a problem.
A safe way to explain the trap
Hypothetical example: A page says a video will load after you complete a “verification” in a separate command window. That request is enough reason to stop. You do not need to run the pasted content to find out what it does. This article intentionally provides no attack command.
Original sources
Attributed synthesis, not original reporting. Examples labeled hypothetical or illustrative are explanatory. Reviewing a source does not independently validate its findings.
- FTC: how to spot a CAPTCHA scam ↗
June 2026 consumer alert; attack boundary and recovery advice read September 26. Exact day not established in retrieved body.
- Microsoft: TerminalFix campaign analysis ↗
August 28, 2026 vendor threat report; initial-access section and clipboard behavior read September 26. No prevalence estimate or product-efficacy claim adopted.