If you read nothing else
- No real website, CAPTCHA or security check will ever ask your team to paste a command into Windows.
- If one does, stop and call whoever looks after your computers. Do not try it a second time.
- Write the rule down and say it out loud at your next staff meeting.
An IT administrator at a managed service provider recently posted a report on Reddit's r/msp forum. It is a short story with a lesson any small business, nonprofit or defense supplier can use this week. Source: Reddit r/msp report.
What happened when an AI chat asked someone to run a command?
A person at a client organization was doing ordinary work in ChatGPT. They had uploaded a PowerPoint and asked for help turning it into investor material.
Partway through, a message appeared in the chat saying the service was seeing elevated automated traffic and that extra security verification was needed. It was signed "OpenAI Security Team" and linked to a page made to look like a verification service.
The person clicked. The page copied a command to their clipboard and told them to press Win + X, open Windows Terminal, paste, and press Enter. The command would have pulled code from an attacker's server and run it.
They tried twice, about 88 seconds apart. The organization's endpoint protection stopped both attempts. The security provider found no sign that anything was downloaded or left behind.
What is not known yet?
Quite a lot. The administrator says they do not know why the message appeared inside the chat. It could have been prompt injection, another kind of manipulation, or an unsafe response from the assistant. They also say they are not claiming OpenAI was compromised.
They checked a copy of the PowerPoint and found nothing malicious, but they note that does not prove the original was identical. They are preserving evidence and reporting the incident to OpenAI. OpenAI has not commented publicly as of this writing.
So please read this as one team's report, not a confirmed pattern. The lesson does not depend on the unanswered questions.
What is ClickFix, and why does it work?
The trap on the other end of that link has a name: ClickFix. A fake verification or error message talks a person into pasting a command into the Windows Run box or a terminal. The person runs the attack themselves, so it looks like their own action. Microsoft has written about the technique in its security blog, and Proofpoint has published a security brief on it. Sources: Microsoft Security blog, "Think before you Click(Fix)"; Proofpoint security brief on ClickFix.
What stands out in this report is where the instruction showed up: inside a chat people already trust. We tend to follow what our assistant tells us. An instruction that arrives in that window borrows that trust.
What rule keeps my team safe?
Nothing legitimate asks you to paste a command into Windows to prove you are human. Not a CAPTCHA, not a chatbot, not a browser warning, not a message with a famous name on it.
If anything tells your team to press Win + R or Win + X and paste, the answer is no. Close the page. Tell someone. That is all it takes.
What can a small organization do this week?
- Say the rule above, in those words, at your next staff meeting and in a short note.
- Check that every computer has endpoint protection that can stop a malicious PowerShell command. In this report it was the only thing between a click and a breach.
- Decide which AI tools your people may use, and for what kind of information. A one page written rule beats guessing.
- Make it normal to report a near miss. The person who clicked twice did what many of us would do. Reporting it quickly is what mattered.
Need help putting this in place?
Cyber Grants Alliance supports small businesses, nonprofits and defense suppliers with in-kind cybersecurity help. Apply for in-kind support and tell us what you are worried about.
Call to action
We will keep watching this one. Follow the Monthly Threat Intelligence for updates, and share this page with the person on your team who answers the phone and opens the email.
