
Humanity, as a collective species, has achieved some truly remarkable things. We have landed on the Moon, decoded the human genome, and invented sliced bread. Yet, if a brightly coloured box pops up on a laptop screen claiming that a browser cannot load a picture of a kitten unless we press three completely random buttons on our keyboard, millions of us will happily comply.
We, as website addicts, have become accustomed to this version of Pavlov’s Dog and the criminal masterminds of the internet know it.
They have stopped bothering with complicated, high-tech hacking tricks to break down our digital front doors. Instead, they have invented something called the ClickFix scam—and it relies entirely on the fact that most people treat computers like magical glowing bricks powered by wizardry.
Here is how it works.
You are casually browsing the web, minding your own business, when suddenly a window pops up. It looks very official. It might claim your video stream has failed, or your document couldn’t load, or—most brilliantly of all—it presents a fake CAPTCHA test asking you to “Prove You Are Human”
Now, normally, proving you are human involves identifying crossing or trying to decide whether a tiny pixelated square contains a bicycle or just a signpost. But the ClickFix scam does something far more insidious. It displays a neat little instruction list:
- Open Terminal
- Press Ctrl + V.
- Press Enter.
To the average user, this looks like a clever technical shortcut. It isn’t. It is the digital equivalent of handing a burglar your front door keys, a cup of tea, and a map showing where you keep the family silver.
When you click that fake button on the website, it secretly copies a nasty chunk of malicious code onto your clipboard. Pressing Opening Terminal (and they might even give yo very clear instructions on how do this) opens the master command box on your computer—the place where deep, structural orders are given. Pressing Ctrl + V pastes the hacker’s hidden virus instructions directly into it. And pressing Enter executes it.
In three keystrokes, you have personally invited a cyber criminal inside to rifle through your passwords, banking details, and personal photos. You did the work for them! It is staggering!
So, how do you avoid falling for this absolute madness? You do not need an expensive degree in computer science, nor do you need to hire a team of IT consultants in suits. You just need to remember one simple, golden rule:
Websites Use the Mouse, Hackers Use the Keys
A legitimate website will NEVER ask you to open a system window, press key combinations, or paste commands into your computer to clear a security check or fix an error. Ever.

Yes, these are instructions for a Windows PC and yes, they are in German…. but the look will be similar.
This is particularly true if you have been looking for instructions to fix an issue you might be having. You may inadvertently – after a very innocent Google search – come across a website that promises to fix this issue by pasting in this command and running it. The question you have to ask yourself is where is this command coming from? It might look like it’s coming from Apple but faking the look of a website is one of the easiest things to do.
DON’T RUN ANY COMMAND YOU DON’T KNOW THE ORIGIN OF

If a pop-up tells you to touch your keyboard—specifically Command + V (Paste) —your fingers should instantly freeze. Treat that prompt with the exact same suspicion you would reserve for a stranger in an alleyway offering to inspect your wallet for counterfeit notes.
Close the tab, shut down the browser, and walk away feeling smug in the knowledge that you were far too clever to be tricked.