How to Secure Microsoft 365 Against Modern Cyber Attacks
If a threat actor logged into one of your employees’ Microsoft 365 accounts right now, how long would it take you to notice?
Curious about the technical details? Read our technical blog on ClickFix Block.
In recent months, a dangerous but convincing social engineering technique has started spreading: the fake CAPTCHA or ClickFix attack. Cybercriminals create a page that looks like a legitimate captcha challenge, something we all trust. But instead of asking you to click on images, the page instructs you to run a command on your computer.
What makes the attack so effective is the use of the clipboard. Without the user realising it, the website automatically places a malicious command in the clipboard. When the user pastes and executes it, the attacker gains control of the device, installs malware, or steals passwords.
At Eye Security, we decided not just to analyse this threat, but to build a solution. That’s why we created ClickFix Block, a free browser extension that prevents this attack before it can succeed.
This attack works because it exploits what users already know and trust. CAPTCHAs are everywhere on the internet and usually associated with security. That is what makes this technique so effective.
Organisations cannot rely solely on employees to recognise phishing attempts. In this case, there are no suspicious emails or red flags. The manipulation happens directly in the browser, at the moment users are least likely to question it.
ClickFix Block was designed with one purpose: break the attack before it has a chance to succeed.
▶️ Watch the demo below to see ClickFix Block stop a fake captcha attack in real time.
With ClickFix Block:
Normal copy and paste continues to work as usual. The extension only monitors suspicious clipboard activity initiated by websites.
Go to the Chrome Web Store.
Click Add to Chrome.
Confirm by clicking Add extension.
Once the extension is installed, the ClickFix Block icon will appear in the top right corner of your browser.
If you don’t see it immediately, click the puzzle piece icon and pin it for quick access.
By clicking on the extension icon, you can:
Any changes you make are applied immediately when the page refreshes.
ClickFix Block is a strong example of how small, targeted measures can disrupt an entire attack technique. By stopping clipboard manipulation in the browser, it removes the critical step that fake CAPTCHAs rely on.
At the same time, we know that cyber threats evolve constantly. That is why we apply the principle of assume breach: even if attackers bypass one layer of defence, there must always be monitoring and response in place to contain the threat. Fake CAPTCHAs are only one of many techniques, and new ones will inevitably follow.
This is why prevention and detection go hand in hand. ClickFix Block lowers the chance of compromise, while ongoing monitoring and response ensure resilience against the attacks of tomorrow.


We are releasing ClickFix Block free of charge as part of our mission to keep Europe safe. It is available for everyone, not just our customers, because the risk does not stop at organisational boundaries.
Access ClickFix Block on the Chrome Web Store.
👉 Bottom line: with ClickFix Block, you can neutralise an entire attack technique with a single extension and protect your organisation from one of the fastest-growing browser-based threats.
If a threat actor logged into one of your employees’ Microsoft 365 accounts right now, how long would it take you to notice?
The world’s most expensive cybersecurity systems have an awkward weakness. They trust the right people.
One in twenty organisations we onboard is already breached when we arrive. This is what our team finds when we deploy MDR across a new customer environment for the first time.