AI-Boosted Phishing and “ClickFix” Scams Hit SMBs

We Live Security · Medium sophistication
Last updated September 22, 2026

The article warns that small and mid-size businesses are facing a squeeze: new risks from AI agents connected to company systems, and faster, more effective versions of familiar scams like phishing. It highlights real-world trends such as QR-code phishing and “ClickFix,” where fake error pages trick users into pasting commands into their own devices. It also notes that attackers can hide malicious instructions in content AI agents retrieve (like web pages or emails), potentially causing data exposure without a user clicking a link.

How the attack works

Attackers are combining familiar social-engineering tactics with AI to make old scams faster and more convincing. Two patterns stand out. First, QR code phishing asks employees to scan a code embedded in an email, often framed as a need to verify or restore access after a supposed login issue, which leads to a fake sign-in page designed to capture credentials. Second, ClickFix scams present a fake error message that instructs a user to paste a command into their own terminal, a tactic now frequently dressed up as AI troubleshooting and hosted on public AI sharing pages to appear legitimate.

Why it succeeds

These scams work because they exploit trust in routine workflows: verifying access, fixing a technical error, or following AI-generated guidance. QR codes sidestep the usual scrutiny given to links, since the scan happens on a phone rather than in a browser where hover-over checks are common. ClickFix relies on urgency and technical framing to get users to act before questioning the source. AI is compounding the problem by making phishing emails significantly more effective, with automated phishing reportedly achieving a much higher click-through rate than standard attempts, letting attackers scale these techniques with less manual effort.

What to watch for

  • Emails that push QR code scanning instead of a normal login link, especially paired with urgent or pressured language
  • Web pages or pop-ups instructing you to copy and paste a command into a terminal, particularly when framed as an AI or system fix
  • Instructions hosted on public sharing pages rather than official IT or vendor support channels
  • Login pages reached after scanning a QR code that don't match the company's real sign-in URL

A less visible risk involves AI agents connected to business systems. Because these agents act through permissions granted by their owner, they are vulnerable to indirect prompt injection, where an attacker hides commands in a webpage, email, or other resource the agent is instructed to fetch. This can potentially expose data without any employee clicking a malicious link.

How to build resistance

  • Treat QR codes in emails as suspicious and verify requests through a known, trusted path such as a bookmarked URL or internal portal
  • Never paste commands into a terminal because a web page or AI troubleshooting message tells you to; confirm with IT or official vendor support first
  • Assume AI-connected tools can be manipulated and restrict what agents can access and send out
  • Establish basic AI governance, including a written policy and visibility into which agents and AI services are running, who connected them, and what permissions they hold, since many SMBs currently lack this oversight

Key findings

  • Many SMBs lack AI governance: the cited survey found “40 percent of the businesses didn’t even have an AI policy.”
  • ESET reports a growing AI-agent supply chain risk: scanning “almost 900,000 unique skills,” it found “more than 25,000… suspicious and more than 3,000 outright malicious,” linked to “credential theft, data exfiltration and remote code execution.”
  • Attackers are using AI to scale proven social-engineering: “AI-automated phishing emails achieve a 54-percent click-through rate versus 12 percent for standard attempts.”
  • “QR code phishing is soaring,” and “ClickFix… asks a user to paste a command into their own terminal,” now “often dressed up as AI troubleshooting.”
  • Indirect prompt injection is highlighted as a practical risk: attackers can “hide commands in a webpage, email or another resource that the agent is instructed to fetch.”

Who’s being targeted

  • Commonly targeted roles: All employees, IT, Engineering, Helpdesk/Service desk, Security/IT management.
  • Affected industries: Small and mid-size businesses (cross-industry).
  • Attack channels: email, website.
  • Impersonated: A trusted business service (e.g., Microsoft 365 / internal file portal), AI support/troubleshooting guidance (hosted on a public AI sharing page).

Red flags to watch for

  • Email pushes QR scanning instead of a normal login link
  • Urgent/pressured language to act quickly
  • Login page after scanning doesn’t match the company’s real sign-in URL
  • A web page instructs you to paste commands into a terminal
  • “Fix” steps are not from an official IT/helpdesk channel
  • Instructions are hosted on a public sharing page rather than an official support site
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is ClickFix and how does it target SMBs?

ClickFix is a scam where a fake error message tricks a user into pasting a command into their own terminal, and it is now often disguised as AI troubleshooting hosted on public AI sharing pages.

Why is QR code phishing effective against small businesses?

QR code phishing bypasses normal link scrutiny because employees scan a code with a phone instead of clicking a link, often under pressure from urgent language claiming a login issue needs fixing.

How does AI increase the risk of phishing for SMBs?

AI-automated phishing emails reportedly achieve a 54 percent click-through rate compared to 12 percent for standard attempts, meaning attackers can scale proven social-engineering tactics more effectively.

What risk do AI agents connected to business systems create?

AI agents can be manipulated through indirect prompt injection, where an attacker hides commands in a webpage, email, or other resource the agent is instructed to fetch, potentially exposing data without a user clicking anything.

Read the video transcript

AI scams are getting sneaky. The new trick? They make YOU do the dangerous part yourself. First, the email: 'Scan this QR code to verify your Microsoft 365 access.' You scan it, a login page pops up, looks normal, but the URL isn’t your real company sign-in. That’s QR code phishing, and it’s soaring. Then there’s ClickFix: a web page says, 'Error: Your session failed. Fix it by running this command in your terminal.' It’s dressed up as AI troubleshooting, hosted on a public AI sharing page, and the command can quietly install malware. Here’s the move: if an email wants you to scan a QR code, or any web page tells you to paste a command, stop and go through our official IT or portal instead, do not follow those on-screen instructions.

Similar attacks

Fake ChatGPT Invoice Email Steals Logins

Fake ChatGPT Invoice Email Steals Logins

Attackers are sending fake ChatGPT billing emails that pressure people to “update payment” within 48 hours to avoid service interruption. The message links to a convincing look‑alike ChatGPT login page via a Google redirect, aiming to steal OpenAI credentials.

September 18, 2026
Fake Helpdesk Passkey Setup Steals Cloud Access

Fake Helpdesk Passkey Setup Steals Cloud Access

The article describes real intrusions where attackers impersonate a company helpdesk and lure employees into "passkey, MFA, or SSO setup" steps. Victims are sent links via text (often to personal phones), leading to account takeover through adversary-in-the-middle phishing or device-code…

September 16, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026
M365 “Direct Send” Abused for Internal-Looking Phish

M365 “Direct Send” Abused for Internal-Looking Phish

Researchers observed a real phishing campaign that abused Microsoft 365’s Direct Send feature to make emails look like they came from the victim organization’s own domain, without compromising an employee account. The campaign was timed to mimic human sending patterns during U.S. Eastern business…

September 14, 2026
Claude Linked to Real Phishing and Credential Theft

Claude Linked to Real Phishing and Credential Theft

Anthropic reports multiple real-world threat groups used Claude to support cyber operations, including credential harvesting and data theft across many victims. The report includes specific, simulation-ready lures such as a fake ESET NOD32 login portal that sends stolen passwords to Telegram and a…

September 11, 2026
Russian Hackers Used AI to Evolve Phishing & Malware

Russian Hackers Used AI to Evolve Phishing & Malware

Anthropic says it disrupted a Russian state-linked campaign that used Claude to continuously rebuild malware when security tools detected it. The group (GTG-20006, linked to Midnight Blizzard/APT29) ran phishing and other human-targeted schemes, including device-code token theft against Microsoft…

September 11, 2026