Imagine one of your staff is browsing the web, hits a page that says “Verify you’re human” or “Click to fix this download,” follows the on-screen instructions exactly as told, and within minutes a criminal on the other side of the world has their saved passwords, active login sessions, and copies of business documents from OneDrive and SharePoint. No suspicious attachment was opened, no obviously dodgy link was clicked. Just a few keystrokes that felt completely normal. This is the trick behind a scam technique security researchers call “ClickFix,” and it’s currently being used to spread a piece of malware called ACR Stealer that specifically targets Microsoft 365 accounts and browser data.
This matters for regional Victorian businesses because so many of us now run our entire operation through Microsoft 365 – email, invoicing, staff rosters, client files, accounting records. If one login gets compromised, an attacker doesn’t just see your inbox, they can potentially access shared drives, send emails as you to customers and suppliers, and quietly harvest sensitive documents for weeks before anyone notices.
Unlike older phishing scams that rely on tricking someone into opening an infected attachment, ClickFix relies on a much simpler psychological trick: it convinces the victim to run the malicious command themselves. Typically it plays out like this:
Because the victim is the one physically typing the commands, many antivirus tools and email filters never get a chance to intervene – there’s no attachment to scan and no obviously malicious link to block. As reported by The Hacker News, Microsoft’s own security team has traced two separate delivery methods using this exact approach to spread ACR Stealer, which then goes hunting for saved browser passwords, active login sessions (meaning it can potentially get into accounts even without knowing the password), PDFs, Microsoft 365 files, and anything synced through OneDrive or SharePoint.
It’s tempting to assume this kind of attack is aimed at big corporations with valuable secrets to steal. In reality, small and medium businesses are frequently softer targets precisely because they tend to have fewer technical safeguards, no dedicated IT security staff watching for unusual activity, and staff who are juggling many roles and may not have had formal cyber awareness training. A stolen Microsoft 365 login from a regional business can be just as valuable to a criminal as one from a large company – it can be used to send convincing invoice fraud emails to real clients, access financial records, or simply be sold on to other criminals.
The other reason this scam works so well is that it doesn’t rely on tricking people with obviously dodgy emails anymore. Modern scam pages can look polished and professional, mimicking legitimate error messages that most people would never think twice about following.
If a staff member sees a message telling them to “copy this code and paste it into the Run box to fix the issue,” that is one of the clearest warning signs of this scam. Legitimate software, websites, and IT support will almost never ask a user to manually paste commands into a system dialog box to solve a browser or website problem. If in doubt, the instruction should never be followed – instead, close the browser tab entirely and report it.
The good news is that this type of attack can be defended against without a huge IT budget, mostly through a mix of staff awareness and some sensible technical settings.
Scams like ClickFix are a reminder that cybersecurity threats keep evolving to get around the defences businesses already have in place. A few years ago, staff training focused mainly on spotting dodgy email attachments and links. Now, criminals are finding new ways to get people to do the damaging step themselves, precisely because it slips past traditional filters. Regular, practical staff awareness training – even short refreshers every few months – remains one of the most cost-effective defences a small business can invest in, alongside the basic technical protections outlined above.
No single measure will stop every attack, but combining staff awareness, MFA, monitoring, and good backup practices creates layers of defence that make it much harder for an attacker to succeed – and much easier for your business to recover quickly if something does slip through.
If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.





(+61) 0412 440 804