Investigation · Fake Software Downloads

Claude ClickFix & Fake Installer Investigation

Hall Attorneys is investigating potential claims involving fake Claude installers promoted through Google search ads and Bing redirects. If a supposed Claude download led to a security incident, cleanup costs, or a loss, we want to hear from you.

Public reporting
October 9

2026 · Push Security and BleepingComputer

Reported target
Mac users

people searching for a Claude download

Final payload
Unknown

not identified in the BleepingComputer report

Answer at a glance

What was reported?

Push Security describes a Google ad for 'claude mac' that passed through a Bing redirect and a compromised retail website before reaching a fake download page. It calls the technique Adception.

The fake page's Copy button supplied a different command from the one displayed. Running it fetched attacker-controlled code. BleepingComputer reported that the final payload remained unknown.

This investigation concerns third-party impersonation. The reviewed sources do not establish a breach of Anthropic's systems or responsibility for any particular loss. Hall Attorneys is evaluating individual experiences, available records, and potential claims.

This is an investigation, not a filed lawsuit by Hall Attorneys. Facts may change as organizations, regulators, courts, or security researchers publish additional information.

  1. Research and public reporting published

    Push Security published its Adception analysis, and BleepingComputer reported on the campaign. The publication date does not establish when every incident occurred.

  2. Hall Attorneys opens investigation

    The firm is seeking accounts from people and businesses affected by a purported Claude download, along with records of resulting costs or losses.

The investigation

What we're reviewing

We are reviewing how people reached a purported installer, what they were asked to do, and whether their records show a resulting security incident or financial harm.

Important distinction

A familiar logo, a search-ad placement, or an ordinary Claude account does not establish involvement in this campaign. This inquiry is separate from the firm's broader frontier AI safety investigation.

Advertising and referral records
Search terms, sponsored-result screenshots, displayed website names, browser history, and approximate click times.
Installation experience
What the page displayed, whether an instruction was copied or run, and any saved screenshots or security alerts.
Possible account or device impact
Professional findings, unfamiliar logins, unauthorized activity, or other evidence connecting an incident to the download attempt.
Costs and losses
Documented cleanup charges, account-recovery expenses, lost funds, downtime, and time spent responding.

Who may want to contact us

Did a Claude download lead to a security incident?

Tell us what happened even if you are unsure which website or advertisement you encountered. We will review the available records before drawing conclusions about your experience.

People who followed a search ad to a purported Claude installer and were prompted to use Terminal.

People who copied or ran an installation instruction and later received a security alert or discovered unauthorized activity.

Businesses responding to an employee's suspected fake software installation.

People with documented cleanup costs, account-recovery expenses, or other losses potentially connected to the download attempt.

What to preserve

Keep the records you already have

Save existing evidence without revisiting a suspicious site or rerunning a command. A brief description is enough for an initial inquiry; arrange a secure way to share sensitive records later.

Search and browsing records

Keep existing screenshots, browser-history entries, search terms, dates, and the name or address displayed in the advertisement.

Installation instructions

Preserve screenshots or records of what you were asked to copy, paste, or run. Ask a security professional to preserve relevant logs safely.

Security findings

Keep antivirus alerts, incident reports, technician findings, and support correspondence, with dates and ticket numbers.

Account activity

Retain unfamiliar-login alerts, password-reset notices, unauthorized-transaction records, and your reports to service providers.

Expenses and disruption

Save cleanup invoices, recovery charges, records of lost funds or downtime, and a dated log of time spent responding.

Reports and responses

Keep complaints to advertising platforms, law enforcement, or consumer-protection agencies and any responses you received.

Investigation focus

Issues under review

Hall Attorneys is evaluating potential consumer claims based on individual evidence. An advertisement or redirect alone does not establish a platform's legal responsibility.

  1. How the advertisement and download page were presented, and which representations people relied on.
  2. What safeguards, review processes, and responses to reports applied to the advertising and referral path.
  3. Whether device or account evidence connects a person's experience to a deceptive installation attempt.
  4. What harm occurred and whether available facts and applicable law support a claim.

Public records reviewed

Sources for the Claude ClickFix incident

Reviewed October 10, 2026. The campaign accounts appear below alongside general ClickFix and malware guidance. General guidance does not establish what happened on any particular device.

Contact the firm

Tell us about a suspected fake Claude download

Include the approximate date, how you found the page, whether you ran an instruction, and any resulting costs or losses. Do not send passwords, recovery codes, access tokens, private keys, or complete financial-account information. Contacting the firm does not by itself create an attorney-client relationship.

Contact Hall Attorneys

Frequently asked questions

Claude ClickFix investigation FAQ

What is ClickFix?

ClickFix is social engineering: a deceptive page persuades someone to run a command, often as an apparent repair, verification, or installation step. Microsoft's background analysis is linked in Sources.

Does clicking an advertisement prove my device was compromised?

No. A click alone does not establish command execution, malware infection, or loss. Record whether you only visited, copied an instruction, or ran it, and preserve any professional security findings.

What should I do if I ran a suspicious installation command?

Stop following the site's instructions and seek help from your IT team or a trusted security professional. The FTC recommends avoiding sensitive account logins on a possibly infected device, updating security software, scanning for malware, and securing affected accounts. Preserve existing records and do not rerun the command to test it.

Has a particular malware payload or victim total been confirmed?

The BleepingComputer report says the final payload was unknown. The reviewed campaign sources do not establish a confirmed victim count or loss total. Individual device and account evidence is needed to assess harm.

Is this an Anthropic data breach or the frontier AI investigation?

This inquiry concerns impersonation of Claude by third parties. The reviewed reporting does not establish an Anthropic data breach. It is separate from Hall Attorneys' broader investigation into unauthorized actions by frontier AI agents.

Has Hall Attorneys filed a lawsuit about this campaign?

Hall Attorneys is investigating potential claims and has not filed a lawsuit concerning this campaign. No recovery is guaranteed, and contacting the firm does not by itself create an attorney-client relationship.

Attorney Advertising

Hall Attorneys is not affiliated with Anthropic or the publishers cited on this page. This page concerns an investigation, not a filed lawsuit by Hall Attorneys. Sending information does not create an attorney-client relationship. Do not send passwords, monitoring codes, complete financial-account numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.