Hackers Stole Your Account (for free)

Hackers Stole Your Account (for free)

Source: YouTube · John Hammond · published Apr 23, 2026 · 15:00

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This video explores the ClickFix social engineering attack technique, which evades traditional security tools like EDR and antivirus by manipulating users through familiar-looking interfaces 0:31.

Key Takeaways:
• Security incidents are typically detected through endpoint detection response (EDR) solutions, antivirus alerts, or logs in SIEM/SOAR systems 0:05
• Certain attacks operate in blind spots where EDR and antivirus lack visibility to detect threats 0:20
• ClickFix is a social engineering technique that tricks users into performing malicious actions through seemingly routine steps 0:36
• The attack leverages familiar interfaces like Google Forms or reCAPTCHA checkboxes to desensitize users to the threat 0:43

The video highlights how social engineering attacks like ClickFix exploit human trust rather than technical vulnerabilities, bypassing traditional security detection methods.

Sources:

  • 0:05 How security incidents are typically detected via EDR and antivirus
  • 0:20 Attacks that lack visibility for traditional security tools
  • 0:36 ClickFix as a social engineering technique
  • 0:43 Examples of familiar interfaces used in ClickFix attacks

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

How do you know when you've had a security incident? How does your team know when you're compromised? Well, usually your endpoint detection response solution or your antivirus flags an alert because it saw something happened or there were some logs thrown into your SIM or your seam solution and there was visibility to detect a threat. But what about attacks where there aren't a lot of options to have that visibility? What about where your EDR and antivirus can't see it? Now, throughout the past year or so, we've talked a lot about clickfix. This attack technique that is social engineering, ultimately tricking the end user to go through just regular steps or instructions that they're pretty desensitized to, like a Google form or this recapture checkbox that says, "I'm not a robot." But then…