NCSC reports increased compromised websites using fake CAPTCHAs worldwide; More than 100,000 sites affected worldwide
Increase in compromised websites with fake CAPTCHAs
07.08.2026 - The NCSC is currently seeing an increase in compromised websites that use fake CAPTCHAs to trick people into running malicious commands and infecting their computers with malware. More than 100,000 websites worldwide are affected. The NCSC is also seeing an increase in the number of Swiss websites being compromised by cybercriminals and used to distribute malware.
CAPTCHAs are small security checks that help website operators protect their sites against unauthorised access by automated programs, known as “bots”. Visitors are generally required to tick a box and then solve a number or image puzzle. Cybercriminals are increasingly exploiting the widespread use of CAPTCHAs and people’s familiarity with them.
In February 2026, the NCSC reported on a social engineering technique known as ClickFix in a weekly review. Cybercriminals create fake CAPTCHAs and supposed error messages on websites to trick visitors into running a malicious command, inadvertently infecting their computers with malware. In recent weeks, the NCSC has observed an increase in compromised websites in Switzerland displaying fake CAPTCHAs to visitors. Most of the affected websites use the WordPress content management system (CMS). More than 100,000 websites worldwide have already been affected. The NCSC notifies the operators of affected websites by email and asks them to remove the malicious content and secure their sites.
The fake CAPTCHAs imitate those used by Cloudflare, a US content delivery network provider, and adapt to the visitor’s language. The compromised website also detects the visitor’s operating system. Windows users are instructed to run a PowerShell command, while macOS users are given a command designed for their operating system. ClickFix therefore targets both Windows and macOS systems.
The NCSC is currently tracking seven cybercriminal campaigns that are attempting to infect computers with ClickFix.
If visitors follow the instructions on a compromised website and run the command, it downloads more malicious code from the internet. Cybercriminals use blockchain technology to store and distribute this code, a technique known as EtherHiding. The code can be retrieved through the web interfaces of RPC providers, which provide access to blockchain networks.
The malware downloaded by the malicious code is usually an infostealer. This type of malware is designed to steal sensitive information such as login credentials, credit card details and cryptocurrency wallet data from the victim’s computer. Popular infostealers such as Vidar are sold on the dark web.
Most of the compromised websites use the WordPress CMS. In recent days, the NCSC has received a growing number of reports from Swiss website operators and web hosting providers concerning the exploitation of two recently disclosed WordPress vulnerabilities. Cybercriminals are exploiting a combination of these vulnerabilities known as “WP2Shell” (CVE-2026-63030 and CVE-2026-60137). WordPress released security updates to address the vulnerabilities on 17 July. However, not all website operators have installed these updates, resulting in WordPress websites being compromised. The NCSC is also aware of cases in which cybercriminals appear to have exploited “WP2Shell” to compromise other websites hosted on the same server by means that are not yet understood.
These compromises may be preparatory steps intended to allow cybercriminals to display fake CAPTCHAs at a later stage and use them to infect website visitors’ computers with malware.
Be wary of instructions to run commands Never run a computer command, such as pressing the Windows key + R, because a website instructs you to do so. Leave the website immediately and, if in doubt, seek advice from an IT professional.
Software updates Make sure that your computer and all installed software are kept up to date.
Antivirus software Make sure that your computer has up-to-date antivirus software installed.
Software updates Keep your content management system (CMS), including all plug-ins and add-ons, up to date. Enable automatic updates wherever possible.
Use MFA If supported by your CMS, enable multi-factor authorisation (MFA) for all accounts.
Secure your CMS Follow the best practices and security guidelines issued by your CMS provider, for example: WordPress Hardening Joomla! Security Checklist TYPO3 Security Guidelines
Restrict access to RPC providers Companies and critical infrastructure operators that do not operate in the fintech sector should restrict outbound connections to RPC providers. A corresponding list is available in the GovCERT.ch archive on GitHub .
Raise awareness Employees should be made aware of the ClickFix technique and taught how to recognise suspicious CAPTCHA prompts.
Increase in compromised websites with fake CAPTCHAs
National Cyber Security Centre NCSC