Episode 55
ClickFix & Phishing Attacks: The Back-to-School Surge
August 28th, 2026
1 hr 2 mins 53 secs
Season 3
About this Episode
Welcome back to the Scinary Information Nexus! While Richard is away enjoying his August hiatus, Brazos, Joseph, and Mario are holding down the fort. With the back-to-school season in full swing, the SOC team has been battling an absolute blazing inferno of cyber threats.
The guys debrief on two major attacks currently hammering networks: highly evasive "ClickFix" malware campaigns and relentless Business Email Compromise (BEC) attacks. Threat actors are getting clever, injecting fake CAPTCHAs into legitimate websites to trick users into running malicious PowerShell scripts.
Meanwhile, credential harvesters are using trusted services like Google Docs to bypass email filtering and build massive databases of compromised accounts. Ultimately, these attacks expose a real problem: modern cybersecurity education is failing.
Because end-users have become overly trusting of automated security tools, they've let their guard down. The crew debates how to fix this broken system, joking about the ineffective "D.A.R.E. program" style of current compliance training.
In this episode, we discuss:
- The massive back-to-school surge in SOC alerts and incidents.
- How ClickFix uses fake CAPTCHAs to trick users into executing malware.
- Why threat actors use trusted sites like Canva and Google Docs to bypass filters.
- The rise of Initial Access Brokers and credential harvesting through BEC.
- Why traditional compliance-based cybersecurity training is failing end-users.
- How to modernize user education with real-world, local examples.
- The debate over implementing consequences for "habitual clickers."
Do you think employees should face real consequences for continuously failing phishing tests? Let's discuss in the comments.
Connect with Scinary Cybersecurity:
https://www.scinary.com
https://x.com/scinarycyber
https://www.linkedin.com/company/scinarycyber/
00:00 Intro
04:30 The ClickFix Epidemic & Fake CAPTCHAs
19:30 BEC & Google Forms Credential Harvesting
31:00 Why Cybersecurity Education is Failing
41:00 Rethinking Training & User Consequences