A customer's website. A supplier's page. A clinic's site you looked up because somebody you know works there. The screen goes gray, a box appears, and the box says: verify you are human.

That part is normal. Your staff has clicked that box ten thousand times.

Then the page tells them what to do next. Press the Windows key and R. Paste. Press Enter.

That is not normal. That is the entire attack.

A real CAPTCHA never asks you to run a command

Every legitimate CAPTCHA asks one of two things of you. Click a box. Or solve a small puzzle, like picking the traffic lights or typing the wavy letters. Cloudflare's version is a checkbox that mostly checks itself.

None of them, ever, ask you to open the Run dialog or paste text into a command window. The Federal Trade Commission put out an alert about this in June, and the wording is worth repeating: real CAPTCHAs will not ask you to run commands on your device. If a CAPTCHA does, you are not verifying anything. Somebody is handing you a script and asking you to press the button yourself.

Why your antivirus does not catch this one

Nothing arrives. That is what makes this pattern different from the phishing you already know about.

There is no attachment for a filter to block. No file to scan. No download that looks wrong. The page quietly copies a command to your clipboard, then walks you through running it with a tool that is already on every Windows computer. Microsoft's security team wrote up a version of this in August. The fake Cloudflare page sends people to Windows Terminal instead of the Run box, because longer commands behave better there, and the page even prints reassuring green text that looks like a successful verification.

Your email filter never sees it. Your antivirus has nothing to inspect, because the command borrows software Windows already trusts. By the time the command reaches out and pulls down the real payload, a person has already given it permission.

This is not a fringe trick. ESET measured these fake-CAPTCHA detections climbing 517 percent over six months, which made it the second most common attack method behind ordinary phishing. Their newer report shows detections up another 108 percent between the second half of 2025 and the first half of 2026.

The website serving the trap is usually just a small business

This is the part I would want an owner to sit with.

The fake CAPTCHA is almost never on a sketchy website. It sits on a real one, usually a normal business site that was broken into and quietly altered. Switzerland's national cyber security centre reported in August that more than 100,000 websites worldwide had been affected, and that most of them ran WordPress.

Then in September, researchers at Netskope identified more than 5,400 compromised sites belonging to more than 2,200 organizations, and told Fox News the sites had little in common except that many belonged to small businesses. Clinics. Plumbing companies. Online stores. The kinds of sites you land on without a second thought.

So the trap on a familiar website is not random chance. Somebody's business website became the bait. It could be a supplier's. It could be a neighbor's shop.

It could be yours.

What happens after someone presses Enter

Usually the first thing installed is a program that steals saved information. It goes after the passwords your browser has remembered, your autofill entries, and the session cookies that keep you logged in.

Those cookies matter most. A stolen session cookie can let someone into your email or your cloud apps without your password, and often without setting off the code you get on your phone. Think of it as a copy of a key to a door that nobody had bothered to close.

From there, access is often sold on to somebody else. That is how one distracted minute on a vendor's website turns into a locked mailbox, or something worse, by the end of the week.

The one rule your whole staff can remember

You do not need to teach anyone how a PowerShell command works. You need one rule, said out loud, more than once, in plain words.

No website ever needs you to press Windows and R, or paste something into a command window, or open Terminal, to prove you are a person.

If a page asks for that, close it. If you genuinely need to be on that site, type the address in yourself and go there directly. That is the whole defense, and it holds on Macs too, where the same trick asks you to paste into Terminal instead.

If someone already pasted the command

Treat it as something for today, not a wait-and-see.

Disconnect the computer from the network. Do not just shut it off and hope. Have someone who can tell you what actually ran look at it, because one of these command chains can leave something behind that survives a restart. Change passwords from a different, clean device, and sign out of active sessions so a stolen cookie stops working. Then check whether the mailbox was set to forward copies of your mail somewhere you did not ask for, because that is a common next step.

Your own website is part of this

If your business has a website, keeping it current is now a security job, not a one-time project. The sites serving these fake CAPTCHAs were mostly running WordPress installs and plugins that had not been updated.

That is boring work. It is also the difference between having a website and having a website that is quietly recruiting other people's employees into a scam. Whoever keeps your site running should be applying those updates and watching for changes nobody asked for. If nobody owns that job right now, that is worth knowing before somebody else finds out for you.

Nobody memorizes a command

People remember a rule. This one is short: if a website asks you to run something, the website is the problem.

We do free assessments that cover the practical version of this for a small business. Whether the computers under your roof would catch something like this. Whether your mail is forwarding anywhere it should not. Whether the website you pay for is actually being kept up. You can act on what we find whether or not you ever hire us.

Call us at (906) 662-4481, or contact us for a free assessment.

Call us at (906) 662-4481, or contact us for a free assessment. >Learn About Managed Services