Please share this warning with your family, friends, colleagues and neighbours. A fake Cloudflare verification page is being used to trick people into infecting their own Windows computers.
This scam is part of a growing group of attacks called ClickFix. A newer version, reported in September 2026, is being called TerminalFix. The page can look polished and convincing, but the warning is very simple:
> If a website asks you to open PowerShell, Command Prompt, Windows Terminal or the Windows Run box and paste in a command, close the page straight away.
Cloudflare, Google, Microsoft and other genuine services will never ask you to run a PowerShell command or press Win + R, paste something and press Enter just to prove that you are human.
What does the fake Cloudflare page look like?
One real example used Cloudflare branding on a website called advanceipscanner[.]com. It included:
- Cloudflare-style logos and wording
- A message about a “secure, high-speed global network”
- The instruction: “Press the key combination ⊞ + R and then CTRL + V, then press Enter”
- Buttons labelled “Fix It” and “Retry”
- A message saying the website needed to review your connection
- A fake-looking Ray ID and “Performance security by Cloudflare” in the footer
The page is designed to make you feel that something is wrong with your internet connection or browser. It may also use phrases such as:
- “Verification required”
- “Manual verification”
- “Fix it”
- “Your connection needs to be reviewed”
- “You have limited time”
These messages are not there to help you. They are there to pressure you into doing something unsafe. If you were unsure, please do not feel silly. That is exactly what the page is designed to do.
What is ClickFix?
ClickFix is a social-engineering scam. It does not exploit you by silently breaking into your computer. Instead, it tricks you into helping the malware run.
When you click the fake verification box or “Fix It” button, the page may silently copy a PowerShell command to your clipboard. You are then told to open the Windows Run box or Terminal and paste it.
The name is deliberately misleading. You are not fixing anything.
> ClickFix means you “fix” nothing. You infect yourself.
This technique can bypass some security warnings because Windows sees you, rather than the website, opening the tool and running the command. That does not make the command safe. It simply means the criminals have persuaded you to start it.
What the hidden PowerShell command does
In the example we reviewed, the copied command was designed to download and run a Windows executable. We are not including the live malicious command here.
In plain English, it works like this:
- It opens Command Prompt and launches PowerShell.
PowerShell is started minimised and with its window hidden, so you cannot easily see what is happening. - It sets a file location.
The malware uses a path such as C:\Users\Public\win31.exe. The Public folder is accessible to all users, which makes it a useful location for malicious files. - It quietly downloads another file.
The command uses PowerShell’s web-download function, known as iwr or Invoke-WebRequest. In the real example, the download came from a hijacked or compromised website address, which we have safely defanged as hxxp://topssportracing[.]com/wp-25. - It saves the download as an executable.
The file is saved locally as win31.exe. - It starts the file.
A PowerShell instruction called Start-Process launches the downloaded programme. This is the point where the malware actually runs. - It opens a legitimate-looking website as a decoy.
The browser may then open advanced-ip-scanner.com, making it look as though the verification worked. This is intended to reduce suspicion.
The downloaded malware could steal passwords, browser information or other sensitive data. It may also install remote-access software that allows criminals to control the computer.
TerminalFix can be even more serious for businesses
Malwarebytes reported the TerminalFix campaign in September 2026. It uses the same basic trick as ClickFix: a fake Cloudflare page copies a command and persuades the visitor to run it.
The difference is what may happen next.
TerminalFix can use several more advanced methods, including hidden files, Windows components made to look harmless, and code hidden inside image files. Microsoft’s research describes something called a persistent reverse tunnel. In plain English, that means one infected work computer could become a hidden doorway back into the business network.
That could allow an attacker to look for:
- Other computers and servers
- Shared folders
- Domain accounts
- Databases and backups
- Business systems that are not directly exposed to the internet
This does not mean every infection will turn into a major breach. But if this happens on a business computer, it should be treated as a serious security incident and checked quickly.
Anyone can encounter this scam
You might think a scam like this would only appear on an obviously risky website. Sadly, that is not always true.
Fake verification pages can appear on:
- Legitimate websites that have been compromised
- Hijacked domains
- Old websites that have been taken over
- Harmful online adverts
- Pages reached through search results, emails or social media
That means you could be visiting a website you have used before and still run into a fake Cloudflare screen. A familiar website is not a guarantee that every page or advert on it is safe.
Malwarebytes’ July 2026 research found fake Google and Cloudflare verification pages being used to deliver several types of malware, including password stealers and remote-access tools. In simple terms, these are designed to steal information or give criminals control of the computer.
What to do if you see the page
Stay calm. The safest thing you can do is stop before you run anything.
- Do not press Win + R.
- Do not paste anything into the Run box, PowerShell, Windows Terminal or Command Prompt.
- Do not click “Fix It”, “Retry” or similar buttons.
- Close the browser tab.
- If the tab will not close, close the whole browser.
- If you clicked the page and think something was copied, clear your clipboard by copying a harmless word such as safe.
Never paste commands from an unexpected website into a Windows tool. Be especially careful with pages showing countdown timers, “manual verification” instructions or urgent warnings.
A real CAPTCHA may ask you to tick a box or select pictures inside the webpage. It will not ask you to open the Run box, Command Prompt, PowerShell or Terminal.
The UK Government’s Stop! Think Fraud campaign recommends taking time to stop, think and check when something feels unexpected. That advice fits this scam perfectly. Genuine organisations do not suddenly ask you to run hidden commands or share security details just to get past a routine verification screen.
What to do if you already ran the command
If you pasted and ran the command, do not panic. But do act quickly.
- Disconnect the computer from the internet. Turn off Wi-Fi or unplug the network cable.
- Do not use that computer for banking, shopping or work email.
- Run a full scan with reputable security software. For a proper check, it is best to have the computer looked at by a trusted IT professional.
- Change your passwords from a different, trusted device. Start with your email account, then move on to banking and other important accounts.
- Contact your bank immediately if you use online banking on the affected computer.
- Report the incident to Action Fraud/Report Fraud.
- Report suspicious websites to the National Cyber Security Centre. Do not go back to the suspicious page just to copy the address.
- If it is a work computer, tell your IT provider immediately and do not reconnect it to the business network until it has been checked.
For businesses, isolate the machine and consider checking other computers for the same signs. TerminalFix may create scheduled tasks (automatic jobs set to run later), registry start-up entries (Windows settings that make things start on boot), or unusual files. A professional investigation is much safer than deleting the first suspicious file you find and hoping the problem has gone away.
Protecting your business from ClickFix and TerminalFix
Good cyber security is not just about software. It also depends on simple, repeatable staff training.
We recommend that businesses:
- Train staff never to paste commands from a website into PowerShell or Terminal.
- Limit who can run powerful Windows command tools where practical.
- Turn on logging and security monitoring so suspicious activity can be spotted.
- Watch for unusual start-up behaviour and unexpected background tasks.
- Keep Windows, browsers and antivirus software fully updated.
- Make sure staff know exactly who to contact if a webpage gives strange technical instructions.
- Use proactive monitoring to spot suspicious downloads, hidden activity and unexpected internet connections.
This is exactly the kind of thing proactive managed IT services can help with. Our managed IT support starts from £295 per month and includes monitoring, patching, security and troubleshooting. We also provide remote support from £55 per hour and on-site support from £79.99 per hour.
Need help? We’re here for you
EB IT Support is a friendly local IT support team based in Boston and serving homes and businesses across Lincolnshire.
If you are not sure whether you have seen this scam, or you think you may already have run the command, please get in touch. We’ll explain everything in plain English, with no jargon, no judgment and no pressure. You do not need to feel embarrassed. These pages are designed to catch people out.
- Call: 01205 627240
- Email: [email protected]
- Free drop-in advice: Monday to Friday, 9am–5pm, at our Boston location
- Response target: We aim to respond to enquiries within three hours during business hours
You can also contact us through our website contact page.
For additional background, see the Malwarebytes research on fake Google and Cloudflare verification pages, the Malwarebytes report on TerminalFix, and Microsoft’s TerminalFix analysis. Further examples and discussion are available through Security Stack Exchange, the Cloudflare Community and the LinkedIn warning shared by Syed Sameer Alvi.
Please share this scam alert with someone who may find it useful. A few minutes of awareness can prevent a stolen password, a compromised computer or a much bigger problem for a family or business in Boston and across Lincolnshire.