Scammers Are Hijacking the “I’m Not a Robot” Check — What Canadians Must Never Do Online
Why This New Scam Matters
A rapidly spreading cyberattack called ClickFix is now targeting Canadians by exploiting one of the most familiar online actions: ticking the “I’m not a robot” CAPTCHA box. Cybercriminals are using this everyday interaction to trick people into installing malware without ever clicking a suspicious link — a major shift in how online fraud works.
Microsoft reports that attackers are manipulating users into typing commands that install malware themselves, bypassing traditional antivirus detection. Once installed, criminals gain access to passwords, banking credentials, crypto wallets, and personal data.
The Scale of the Threat in Canada
ClickFix attacks surged 517% between 2024 and 2025, making it one of the fastest‑growing cybercrime methods globally.
Canadian victims are losing millions:
112,000 fraud reports were filed in 2025
Identity theft topped the list with 8,403 incidents
Total reported losses reached $704 million
But the real number is far higher — the Competition Bureau estimates only 5–10% of fraud cases are ever reported.
How the ClickFix Scam Works
ClickFix is dangerous because victims unknowingly perform the malicious steps themselves:
Attackers redirect users to a fake verification page mimicking a CAPTCHA
The page instructs users to “fix” a supposed verification error
Victims type commands into their device, unknowingly installing malware
Once installed, criminals gain broad access to the device and can sell stolen data on underground markets.
What Canadians Must Never Do Online
To protect yourself from ClickFix and similar scams:
1. Never type commands into your device because a webpage tells you to
Legitimate CAPTCHA pages never ask users to enter system commands.
2. Never trust a verification page that looks slightly “off”
Fake CAPTCHA pages often mimic real ones but include unusual prompts or error messages.
3. Never assume antivirus will catch everything
ClickFix bypasses detection because victims install the malware themselves.
4. Never ignore browser warnings
If your browser flags a page as unsafe, close it immediately.
5. Never reuse passwords across accounts
Credential theft is a major goal of ClickFix attackers.
How to Stay Safe
Enable multi‑factor authentication (MFA)
Use a password manager
Keep Windows, macOS, and browsers updated
Monitor banking and crypto accounts for unusual activity
Report suspicious pages to the Canadian Anti‑Fraud Centre