---
title: "ClickFix attacks are tricking Mac and Windows users into hacking themselves"
description: "If you clicked on a fake HBO Max ad on Reddit in the past week, you might have fallen victim to a rising \"ClickFix\" security threat."
author: "Zack Whittaker"
section: ai-tech
published: 2026-09-15T03:31:08.557949+00:00
canonical: https://valorandventures.media/article/83722851-f12f-4e67-9bec-ea35df117008
publisher: "Valor & Ventures Media"
source: "TechCrunch"
source_url: https://techcrunch.com/2026/09/14/clickfix-attacks-are-tricking-mac-and-windows-users-into-hacking-themselves/
access: free
---

# ClickFix attacks are tricking Mac and Windows users into hacking themselves

*If you clicked on a fake HBO Max ad on Reddit in the past week, you might have fallen victim to a rising "ClickFix" security threat.*

## Executive Summary

In a recent report published by TechCrunch, security journalist Zack Whittaker highlights a growing cyber threat known as "ClickFix" attacks, which are currently targeting both Mac and Windows operating systems. The warning comes after a specific malicious campaign was detected on the social media platform Reddit, where bad actors deployed fraudulent advertisements disguised as promotions for the streaming service HBO Max. According to the outlet, users who interacted with these deceptive ads over the past week may have unwittingly compromised their own devices, reflecting a dangerous trend in modern social engineering tactics. The concept of "ClickFix" represents a sophisticated shift in how cybercriminals compromise personal and enterprise systems. Rather than relying solely on complex technical exploits to bypass system defenses, these attacks trick users into executing malicious actions themselves. The TechCrunch report emphasizes that both major desktop operating systems—macOS and Windows—are vulnerable to these deceptive prompts. By manipulating users into interacting with fraudulent elements, the attackers effectively bypass traditional perimeter defenses by leveraging the authorized privileges of the system's own users. The specific instance highlighted by TechCrunch involved a highly targeted campaign on Reddit utilizing fake HBO Max advertisements. This method of distribution exploits the trust users place in familiar brands and mainstream social media platforms. By clicking on these malicious ads, users are directed into a workflow designed to compromise their machines. This incident underscores the growing risk of malvertising on public forums, where threat actors can easily blend in with legitimate advertisers to deliver malicious payloads to unsuspecting audiences. While the TechCrunch report focuses on the immediate threat posed by the fake HBO Max campaign, the rise of "ClickFix" attacks points to a broader systemic challenge in cybersecurity. As operating system developers implement more robust built-in security controls, attackers are increasingly focusing on the human element as the weakest link. By convincing users that they are fixing a minor technical issue or accessing legitimate promotional content, attackers can achieve full system access without needing to deploy zero-day exploits or defeat advanced endpoint protection tools. For business executives, founders, and organizational leaders within the Valor & Ventures community, this development highlights the critical importance of continuous user education and robust endpoint security. Because "ClickFix" tactics rely on users actively participating in their own compromise, traditional network-level defenses may not be sufficient to halt these intrusions. Leaders must ensure their teams are trained to recognize suspicious prompts and understand that even trusted platforms like Reddit can host malicious advertisements. Maintaining a culture of cybersecurity vigilance remains paramount to safeguarding enterprise data against increasingly deceptive social engineering strategies.

## Article

If you clicked on a fake HBO Max ad on Reddit in the past week, you might have fallen victim to a rising "ClickFix" security threat.
— Zack Whittaker · TechCrunch
Read the full report at TechCrunch: https://techcrunch.com/2026/09/14/clickfix-attacks-are-tricking-mac-and-windows-users-into-hacking-themselves/

## Citations

1. Claim: “If you clicked on a fake HBO Max ad on Reddit in the past week, you might have fallen victim to a rising "ClickFix" security threat.” — [TechCrunch](https://techcrunch.com/2026/09/14/clickfix-attacks-are-tricking-mac-and-windows-users-into-hacking-themselves/) — Originating report.

---

Originally published by TechCrunch: https://techcrunch.com/2026/09/14/clickfix-attacks-are-tricking-mac-and-windows-users-into-hacking-themselves/
