# Claude ClickFix & Fake Installer Investigation Canonical overview: https://hallattorneys.com/investigations/claude-clickfix Published: October 10, 2026 Last reviewed: October 10, 2026 Status: Hall Attorneys is investigating potential claims and has not filed a lawsuit concerning this campaign. Hall Attorneys is investigating potential claims involving fake Claude installers promoted through Google search ads and Bing redirects. If a supposed Claude download led to a security incident, cleanup costs, or a loss, we want to hear from you. ## Snapshot Researchers reported a macOS installer impersonation campaign on October 9, 2026. ClickFix tricks people into running commands presented as routine installation or troubleshooting. The reviewed reports provide no confirmed victim count or total losses. Public reporting: October 9 (2026 · Push Security and BleepingComputer) Reported target: Mac users (people searching for a Claude download) Final payload: Unknown (not identified in the BleepingComputer report) ## What was reported? Push Security describes a Google ad for 'claude mac' that passed through a Bing redirect and a compromised retail website before reaching a fake download page. It calls the technique Adception. The fake page's Copy button supplied a different command from the one displayed. Running it fetched attacker-controlled code. BleepingComputer reported that the final payload remained unknown. This investigation concerns third-party impersonation. The reviewed sources do not establish a breach of Anthropic's systems or responsibility for any particular loss. Hall Attorneys is evaluating individual experiences, available records, and potential claims. ## Timeline October 9, 2026 — Research and public reporting published Push Security published its Adception analysis, and BleepingComputer reported on the campaign. The publication date does not establish when every incident occurred. October 10, 2026 — Hall Attorneys opens investigation The firm is seeking accounts from people and businesses affected by a purported Claude download, along with records of resulting costs or losses. ## What we're reviewing We are reviewing how people reached a purported installer, what they were asked to do, and whether their records show a resulting security incident or financial harm. A familiar logo, a search-ad placement, or an ordinary Claude account does not establish involvement in this campaign. This inquiry is separate from the firm's broader frontier AI safety investigation. Advertising and referral records: Search terms, sponsored-result screenshots, displayed website names, browser history, and approximate click times. Installation experience: What the page displayed, whether an instruction was copied or run, and any saved screenshots or security alerts. Possible account or device impact: Professional findings, unfamiliar logins, unauthorized activity, or other evidence connecting an incident to the download attempt. Costs and losses: Documented cleanup charges, account-recovery expenses, lost funds, downtime, and time spent responding. ## Did a Claude download lead to a security incident? Tell us what happened even if you are unsure which website or advertisement you encountered. We will review the available records before drawing conclusions about your experience. People who followed a search ad to a purported Claude installer and were prompted to use Terminal. People who copied or ran an installation instruction and later received a security alert or discovered unauthorized activity. Businesses responding to an employee's suspected fake software installation. People with documented cleanup costs, account-recovery expenses, or other losses potentially connected to the download attempt. ## Keep the records you already have Save existing evidence without revisiting a suspicious site or rerunning a command. A brief description is enough for an initial inquiry; arrange a secure way to share sensitive records later. Search and browsing records: Keep existing screenshots, browser-history entries, search terms, dates, and the name or address displayed in the advertisement. Installation instructions: Preserve screenshots or records of what you were asked to copy, paste, or run. Ask a security professional to preserve relevant logs safely. Security findings: Keep antivirus alerts, incident reports, technician findings, and support correspondence, with dates and ticket numbers. Account activity: Retain unfamiliar-login alerts, password-reset notices, unauthorized-transaction records, and your reports to service providers. Expenses and disruption: Save cleanup invoices, recovery charges, records of lost funds or downtime, and a dated log of time spent responding. Reports and responses: Keep complaints to advertising platforms, law enforcement, or consumer-protection agencies and any responses you received. ## Investigation focus Hall Attorneys is evaluating potential consumer claims based on individual evidence. An advertisement or redirect alone does not establish a platform's legal responsibility. How the advertisement and download page were presented, and which representations people relied on. What safeguards, review processes, and responses to reports applied to the advertising and referral path. Whether device or account evidence connects a person's experience to a deceptive installation attempt. What harm occurred and whether available facts and applicable law support a claim. ## Sources Reviewed October 10, 2026. The campaign accounts appear below alongside general ClickFix and malware guidance. General guidance does not establish what happened on any particular device. Adception: malvertising another search engine's search results to redirect to a malicious page Push Security · Luke Jennings — October 9, 2026 https://pushsecurity.com/blog/adception-malvertising-another-search-engines-search-results The researchers' original account of the advertising, redirect, and fake installation sequence. Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks BleepingComputer · Lawrence Abrams — October 9, 2026 https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-bing-redirects-to-push-claude-clickfix-attacks/ Reporting on the campaign and the unresolved final payload. Think before you Click(Fix): Analyzing the ClickFix social engineering technique Microsoft Security — August 21, 2025 https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/ Background on deceptive prompts that persuade people to execute commands; a separate general analysis, not confirmation of this campaign's outcome. Malware: How To Protect Against, Detect, and Remove It Federal Trade Commission — April 2025 https://consumer.ftc.gov/articles/malware-how-protect-against-detect-and-remove-it Consumer guidance on suspicious software ads, device security, account protection, and seeking trusted technical help. ## Frequently asked questions What is ClickFix? ClickFix is social engineering: a deceptive page persuades someone to run a command, often as an apparent repair, verification, or installation step. Microsoft's background analysis is linked in Sources. Does clicking an advertisement prove my device was compromised? No. A click alone does not establish command execution, malware infection, or loss. Record whether you only visited, copied an instruction, or ran it, and preserve any professional security findings. What should I do if I ran a suspicious installation command? Stop following the site's instructions and seek help from your IT team or a trusted security professional. The FTC recommends avoiding sensitive account logins on a possibly infected device, updating security software, scanning for malware, and securing affected accounts. Preserve existing records and do not rerun the command to test it. Has a particular malware payload or victim total been confirmed? The BleepingComputer report says the final payload was unknown. The reviewed campaign sources do not establish a confirmed victim count or loss total. Individual device and account evidence is needed to assess harm. Is this an Anthropic data breach or the frontier AI investigation? This inquiry concerns impersonation of Claude by third parties. The reviewed reporting does not establish an Anthropic data breach. It is separate from Hall Attorneys' broader investigation into unauthorized actions by frontier AI agents. Has Hall Attorneys filed a lawsuit about this campaign? Hall Attorneys is investigating potential claims and has not filed a lawsuit concerning this campaign. No recovery is guaranteed, and contacting the firm does not by itself create an attorney-client relationship. ## Tell us about a suspected fake Claude download Include the approximate date, how you found the page, whether you ran an instruction, and any resulting costs or losses. Do not send passwords, recovery codes, access tokens, private keys, or complete financial-account information. Contacting the firm does not by itself create an attorney-client relationship. Contact: https://hallattorneys.com/connect