How does the scam work?
A fake page displays a familiar “I am not a robot” check, then asks you to open a system window and paste a command. The page may already have placed that command in the clipboard. When you press Enter, you are not confirming your identity — you are running content on your computer.
The attack may begin with a message impersonating a booking service, business portal or other familiar platform. A familiar name does not prove who controls the domain.
Where does a legitimate check end?
A legitimate CAPTCHA stays in the browser. It may ask for a click, image selection or another short interaction with the page. It does not need you to:
- open Windows Run, PowerShell, Command Prompt or a terminal;
- paste text you did not copy yourself;
- disable device protection;
- download a program, extension or profile;
- allow remote access to your computer.
Stop if you see any of these requests.
Check the service safely
- Close the tab without following the proposed steps.
- Do not return through the same link in the message.
- Open the official app or enter a known service address yourself.
- If the message mentions an account, booking or payment, check it inside the official account.
- Report a work-related message to your IT or security team.
If you already ran the command
- Disconnect the device from the network if you can do so without disrupting a critical process.
- Do not enter new passwords or use banking services on that device.
- Record the time, page address and steps you took. Do not run the command again to capture evidence.
- Contact the relevant technical support or security team for a device review.
- From another trusted device, change passwords for accounts used after the event and review active sessions.
- Report the incident promptly if business or financial systems may have been accessible.