Skip to main content

Your Website Could Be Infecting Your Customers: The Fake Cloudflare Scam Hitting Australian Businesses

There is a scam running through Australian small business websites right now, and most owners only find out once the damage is done.It looks completely harmless. Someone lands on your website and sees what appears to be a routine security check, the familiar “Verify you are human” box that millions of legitimate sites use. They tick it. Nothing seems wrong. But that page is fake. It was quietly injected into your website by an attacker, and it is about to walk your own customer through infecting their computer.The Australian Signals Directorate has already issued a public advisory about this campaign, warning that it is targeting Australian organisations through compromised WordPress websites. Security researchers tracking the same campaign identified more than 250 infected sites across at least a dozen countries, with Australia named among them.If your business runs on WordPress, this is your problem whether you know about it yet or not.

What the scam actually does

The attack is known in the security industry as ClickFix. It fixes nothing. It tricks the visitor into doing the attacker’s work. Here is how it unfolds.Step one: your website gets compromised. Attackers get in through an outdated plugin, a weak or reused administrator password, or an admin login page left exposed to the internet. They do not deface anything, because a defacement gets noticed and fixed. Instead they add a small piece of hidden code so your site keeps running normally while doing something extra in the background.Step two: your visitor sees a fake verification page. That hidden code shows a convincing copy of a Cloudflare or CAPTCHA verification screen. Cloudflare is a legitimate service sitting in front of a large share of the web, and it shows these checks constantly, so almost nobody questions one.Step three: the clipboard is hijacked. The moment the visitor clicks the checkbox, the page silently copies a command onto their clipboard. They copied nothing themselves and have no idea it happened.Step four: the visitor is told to “complete verification”. The fake page gives friendly instructions. Press the Windows key and R together. Press Ctrl and V. Press Enter.That instruction is the entire attack. The Windows key plus R opens the Run box, a small built in Windows tool that launches programs by name. Ctrl and V pastes the hidden command that the fake page put there. Enter runs it.The command tells Windows to reach out to a server the attacker controls and run whatever it finds there. In this Australian campaign, that has largely been Vidar Stealer, a piece of information stealing software that has been in circulation since 2018. It goes looking for saved browser passwords, autofill data, multi factor authentication tokens, cryptocurrency wallet files, and session cookies.Session cookies are the part most business owners underestimate. A session cookie is the small file your browser holds that keeps you logged in to a service. Steal a valid one and you walk straight into that account with no password and no two factor code required. The login screen never fires. No alert is triggered.

Why your security software does not stop it

This is the uncomfortable part. Firewalls, email filters and antivirus tools are built to catch malicious files and malicious traffic. This attack sends neither, at least not at the point where those tools are watching.There is no attachment to scan, no dodgy download to block, and no software vulnerability being exploited. A person read an instruction on a webpage and typed it into their own computer. As far as Windows is concerned, the owner of the machine asked for it. That is why the technique has spread so fast, and why standard small business security tools miss it.

What it costs your business

Your search rankings

Google actively scans for compromised websites. When it finds injected code, your listings can be flagged, and in serious cases dropped from results altogether. Chrome and Firefox may show a full page red warning to anyone trying to visit. Organic traffic does not dip in that situation. It falls off a cliff, sometimes within a day.Recovery is slow. Cleaning the site is only step one. You then request a review and wait for the warning to lift, and rankings that took years to build can take months to come back.

Your leads

Every visitor who hits a browser warning is gone. So is every visitor who reaches the fake verification page, gets suspicious, and leaves. Meanwhile your Google Ads spend keeps running against a site that is either blocked or hostile to the people clicking through. Most businesses notice the ad bill before they notice the enquiry drought.

Your customers’ trust

This one outlasts the technical clean up. A customer whose bank logins or business email get drained after visiting your website will connect those two events, and they will tell people. For a local business built on referral, that costs far more than the remediation invoice.

Your obligations

If customer data in your systems is exposed, Australian notifiable data breach obligations may come into play. That is a question for your legal adviser, but it belongs on your radar now rather than as a surprise later.None of this is theoretical. The Australian Signals Directorate recorded around 84,700 cybercrime reports in 2024 to 2025, roughly one every six minutes, with the average self reported cost to a small business sitting at $56,600 and rising.

The one rule worth teaching everyone

Say this to your staff, your family and your clients, and say it plainly.No legitimate website will ever ask you to press Windows + R, or to paste anything into PowerShell or a Terminal window. Those are command tools built into Windows and Mac that run instructions straight on the machine. Websites have no business sending you there.Not Cloudflare. Not Google. Not Microsoft. Not your bank. If a page asks, close the tab. There is no exception to learn and no edge case to remember.If someone has already followed those steps on a work machine, treat that computer as compromised. Disconnect it from the network, then change the important passwords from a different, clean device. Start with email, because email resets everything else.

Get your website checked properly

Most owners cannot tell by looking. Injected code is written to hide from the person who runs the site while showing itself to first time visitors. Your homepage can look perfectly normal to you while serving a fake verification screen to everyone else.A proper security audit is the only reliable answer. That means checking your site’s files and database for injected code, reviewing plugins and user accounts, confirming your backups actually restore, and closing the entry points that let attackers in to begin with.LaunchSmart works with Sydney and Melbourne businesses on exactly this. If your site runs on WordPress, if your traffic has dropped without explanation, or if you just want to know where you stand before something goes wrong, we can help.Book a website security audit with LaunchSmartA clean website is not only a security matter. Your rankings, your leads and your reputation all sit on the same foundation.