In an authoritative intelligence dispatch verified through TechCrunch, significant international developments have emerged regarding ClickFix attacks are tricking Mac and Windows users into hacking themselves. Observers across key diplomatic, corporate, and policy corridors are actively parsing the immediate impact, as corroborated by verified wire filings. If you clicked on a fake HBO Max ad on Reddit in the past week, you might have fallen victim to a rising 'ClickFix' security threat. Disrupt 2026: OpenAI, Anthropic, Replit, and more take over 6 industry stages. 25% off tickets now TechCrunch Desktop Logo TechCrunch Mobile Logo LatestStartupsVentureAppleSecurityAIAppsDisrupt 2026 EventsPodcastsNewsletters SearchSubmit Site Search Toggle Mega Menu Toggle Topics Latest ClickFix attacks are tricking Mac and Windows users into hacking themselves Zack Whittaker 11:08 AM PDT · September 14, 2026 If you clicked on an HBO Max ad on Reddit over the past week, you might want to check your computer for malware. These so-called “ClickFix” attacks have quickly become one of the rising cybersecurity threats of 2026, and they’re getting both sneakier and compromising people’s devices with greater frequency. Until recently, ClickFix attacks were a rarity, capitalizing on people searching the web for quick tech fixes. They have since evolved into a massive international effort to hack into people’s computers. The attacks involve fake websites, or legitimate websites that have been hacked, which display a message that appears to look like a CAPTCHA or an anti-bot checkbox. Once clicked, a prompt appears asking the user to perform a “check” to proceed, which gives instructions to copy and paste a string of text into the user’s Windows command prompt or Mac Terminal app. As soon as the user hits return, they unwittingly and instantly install info-stealing malware on their computer, capable of immediately stealing their passwords, access to their logged-in accounts, and crypto wallets. Since the user is working in the computer’s terminal, which lets them interact directly with the operating system using text-based commands, many of these attacks evade antivirus and security defense tools. Security researchers now say that the latest ClickFix campaign they’ve seen involved hackers posting fake ads on Reddit, linking to a page that looks like HBO Max, but contains a ClickFix lure that tricks people into hacking themselves. The hackers compromised the official HBO Max’s account on Reddit that was then used to post hundreds of fake but real-looking adverts to the news-sharing site, according to security researchers at Hudson Rock and a thread on Reddit’s cybersecurity subreddit. It’s unclear how many people clicked on these fake ads or how many were ultimately compromised as a result. Warner Brothers Discovery, which owns HBO, did not respond to a request for comment; neither did Reddit.
The underlying catalysts behind these events trace back to evolving structural dynamics across the Tech & AI landscape. Over recent quarters, multilateral authorities and market participants have navigated mounting volatility, heightening the urgency of coordinated responses and policy alignment.
Senior analysts and industry stakeholders underscore that strategic transparency remains paramount. As institutional delegations evaluate risk models and operational contingencies, secondary dispatches indicate that further compliance directives and consultative reviews will be initiated in the coming cycle.
Broader economic and regulatory ramifications are projected to ripple across interconnected regional ecosystems. Market analysts note that supply chains, capital allocations, and policy frameworks must swiftly assimilate these verified updates to insulate against systemic bottlenecks.
The Global Post's editorial desk will continue rigorous monitoring of this developing story, with periodic updates provided as official statements and primary documentation are released by relevant governing bodies.