Search and browsing records
Keep existing screenshots, browser-history entries, search terms, dates, and the name or address displayed in the advertisement.
Hall Attorneys is investigating potential claims involving fake Claude installers promoted through Google search ads and Bing redirects. If a supposed Claude download led to a security incident, cleanup costs, or a loss, we want to hear from you.
2026 · Push Security and BleepingComputer
people searching for a Claude download
not identified in the BleepingComputer report
Answer at a glance
Push Security describes a Google ad for 'claude mac' that passed through a Bing redirect and a compromised retail website before reaching a fake download page. It calls the technique Adception.
The fake page's Copy button supplied a different command from the one displayed. Running it fetched attacker-controlled code. BleepingComputer reported that the final payload remained unknown.
This investigation concerns third-party impersonation. The reviewed sources do not establish a breach of Anthropic's systems or responsibility for any particular loss. Hall Attorneys is evaluating individual experiences, available records, and potential claims.
This is an investigation, not a filed lawsuit by Hall Attorneys. Facts may change as organizations, regulators, courts, or security researchers publish additional information.
Push Security published its Adception analysis, and BleepingComputer reported on the campaign. The publication date does not establish when every incident occurred.
The firm is seeking accounts from people and businesses affected by a purported Claude download, along with records of resulting costs or losses.
The investigation
We are reviewing how people reached a purported installer, what they were asked to do, and whether their records show a resulting security incident or financial harm.
Important distinction
A familiar logo, a search-ad placement, or an ordinary Claude account does not establish involvement in this campaign. This inquiry is separate from the firm's broader frontier AI safety investigation.
Who may want to contact us
Tell us what happened even if you are unsure which website or advertisement you encountered. We will review the available records before drawing conclusions about your experience.
People who followed a search ad to a purported Claude installer and were prompted to use Terminal.
People who copied or ran an installation instruction and later received a security alert or discovered unauthorized activity.
Businesses responding to an employee's suspected fake software installation.
People with documented cleanup costs, account-recovery expenses, or other losses potentially connected to the download attempt.
What to preserve
Save existing evidence without revisiting a suspicious site or rerunning a command. A brief description is enough for an initial inquiry; arrange a secure way to share sensitive records later.
Keep existing screenshots, browser-history entries, search terms, dates, and the name or address displayed in the advertisement.
Preserve screenshots or records of what you were asked to copy, paste, or run. Ask a security professional to preserve relevant logs safely.
Keep antivirus alerts, incident reports, technician findings, and support correspondence, with dates and ticket numbers.
Retain unfamiliar-login alerts, password-reset notices, unauthorized-transaction records, and your reports to service providers.
Save cleanup invoices, recovery charges, records of lost funds or downtime, and a dated log of time spent responding.
Keep complaints to advertising platforms, law enforcement, or consumer-protection agencies and any responses you received.
Investigation focus
Hall Attorneys is evaluating potential consumer claims based on individual evidence. An advertisement or redirect alone does not establish a platform's legal responsibility.
Public records reviewed
Reviewed October 10, 2026. The campaign accounts appear below alongside general ClickFix and malware guidance. General guidance does not establish what happened on any particular device.
Push Security · Luke Jennings ·
The researchers' original account of the advertising, redirect, and fake installation sequence.
Read source: Adception: malvertising another search engine's search results to redirect to a malicious pageBleepingComputer · Lawrence Abrams ·
Reporting on the campaign and the unresolved final payload.
Read source: Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksMicrosoft Security ·
Background on deceptive prompts that persuade people to execute commands; a separate general analysis, not confirmation of this campaign's outcome.
Read source: Think before you Click(Fix): Analyzing the ClickFix social engineering techniqueFederal Trade Commission ·
Consumer guidance on suspicious software ads, device security, account protection, and seeking trusted technical help.
Read source: Malware: How To Protect Against, Detect, and Remove ItContact the firm
Include the approximate date, how you found the page, whether you ran an instruction, and any resulting costs or losses. Do not send passwords, recovery codes, access tokens, private keys, or complete financial-account information. Contacting the firm does not by itself create an attorney-client relationship.
Frequently asked questions
ClickFix is social engineering: a deceptive page persuades someone to run a command, often as an apparent repair, verification, or installation step. Microsoft's background analysis is linked in Sources.
No. A click alone does not establish command execution, malware infection, or loss. Record whether you only visited, copied an instruction, or ran it, and preserve any professional security findings.
Stop following the site's instructions and seek help from your IT team or a trusted security professional. The FTC recommends avoiding sensitive account logins on a possibly infected device, updating security software, scanning for malware, and securing affected accounts. Preserve existing records and do not rerun the command to test it.
The BleepingComputer report says the final payload was unknown. The reviewed campaign sources do not establish a confirmed victim count or loss total. Individual device and account evidence is needed to assess harm.
This inquiry concerns impersonation of Claude by third parties. The reviewed reporting does not establish an Anthropic data breach. It is separate from Hall Attorneys' broader investigation into unauthorized actions by frontier AI agents.
Hall Attorneys is investigating potential claims and has not filed a lawsuit concerning this campaign. No recovery is guaranteed, and contacting the firm does not by itself create an attorney-client relationship.
Attorney Advertising
Hall Attorneys is not affiliated with Anthropic or the publishers cited on this page. This page concerns an investigation, not a filed lawsuit by Hall Attorneys. Sending information does not create an attorney-client relationship. Do not send passwords, monitoring codes, complete financial-account numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.