This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Cybersecurity
ClickFix uses fake CAPTCHA in attacks
In this security check, users are usually asked to solve a math problem or select traffic lights, cars, bridges, etc., in images. Unauthorized fake CAPTCHA messages are inserted, prompting visitors to confirm they are humans and not robots by performing specified actions. Following the scammers' instructions (as described above), the user activates a virus designed to steal sensitive information. Ignore and close pop-up windows with suspicious CAPTCHA or updates. If infection is suspected, immediately change passwords on a secure device, contact IT specialists, and reinstall the device. Report sites where attackers have inserted fake CAPTCHA to CERT.LV by writing to cert@cert.lv. Regularly update your content management system (CMS) and associated components—plugins, frameworks, themes, and libraries; enable two-factor authentication (2FA) for admin access; monitor changes and traffic on your site to detect potential compromises.