AI at Work
The Deck Was Fine. The Chat Wasn't: Why Your Team Never Pastes What an AI Tool Says to Run
October 10, 2026 · Next Level Marketing Team
Picture an ordinary afternoon. Someone on the team uploads a deck to an AI assistant and asks for help turning it into investor material. That is exactly the kind of job marketing teams hand to AI tools now. A recent report shows how one of those afternoons went sideways, and why the fix is a rule, not a tool. The short version: an AI tool can suggest. It never gets to tell your team to run something on their computer.
Key takeaways
- A user reported by an IT administrator was working on a presentation in ChatGPT when a message signed "OpenAI Security Team" sent them to a fake verification page.
- The page told them to press Win + X, open Windows Terminal and paste a command. Endpoint protection stopped two attempts.
- The cause is unknown, and the administrator is not claiming OpenAI was compromised. OpenAI has not commented publicly as of October 10, 2026.
- The trick is called ClickFix. It works by getting the person to run the attack themselves.
- The rule for your team: nothing an AI tool or a web page says is a reason to paste a command into Windows.
What was reported?
An IT administrator at a managed service provider posted the incident on Reddit's r/msp forum. A person at a client organization had uploaded a PowerPoint to ChatGPT and asked for help turning the material into content for an investor presentation.
Instead of help with the deck, the chat showed a message saying the service was seeing elevated automated traffic and that extra security verification was needed. It was signed "OpenAI Security Team" and linked to a page imitating a verification service. The message appeared more than once while the user tried to work.
The page copied a command to the clipboard and told the user to press Win + X, open Windows Terminal, press Ctrl + V and press Enter. The command used PowerShell to fetch content from an attacker's domain and run it. The user tried twice, about 88 seconds apart. Endpoint protection stopped the PowerShell process both times, and the security provider found no sign of a payload download or persistence.
What do we not know?
The administrator does not know why the message appeared. Prompt injection, another form of conversation manipulation and an unsafe model response were all named as possibilities, and none was confirmed. They checked a copy of the PowerPoint and found nothing malicious, while noting that this does not prove the original was identical.
They say they are not claiming OpenAI's infrastructure was compromised, and they are reporting the incident to OpenAI. This is one team's account, so we are not calling it a trend. The rule below holds either way.
What is ClickFix?
ClickFix is a social engineering technique. A fake verification or error message persuades someone to paste a command into the Windows Run box or a terminal. The person starts the attack with their own hands, which is why it slips past people who would never open a strange attachment. Microsoft documented it in its security blog in August 2025, and Proofpoint published a security brief on it in November 2024.
Why should a marketing team care?
Because your team lives in these tools. Decks, ad copy, reports and client files all go through AI assistants, often quickly and often under a deadline. A notice that appears inside the tool you already trust reads like part of the job.
That is the real lesson of this report. We treat an email with a strange link as suspect. We have not yet learned to treat a message inside a chat window the same way.
What rule should we adopt?
Write it on one line and put it where the team will see it: an AI tool or a web page never gets to tell us to paste a command into Windows. If one does, we close it and tell the person who handles IT.
Add three habits around it. Keep a short list of the AI tools the team may use and what files may go into them. Make sure every computer has endpoint protection that can stop a malicious PowerShell command, since that was the control that held here. And make reporting a near miss normal, so nobody hides a click.
How do we keep using AI tools without the worry?
Use them for what they do well: drafting, outlining, summarizing, brainstorming. Keep them away from the keyboard commands on your machine. If a task truly needs a command run on a computer, that is an IT task, and IT can check where the instruction came from before anyone runs it.
A good test for any tool in your workflow: if it asked for something you would not hand a stranger on the phone, it does not get it from a chat window either.
Reference: Reddit r/msp: A ChatGPT conversation directed a user to a fake verification site
Frequently asked questions
Is ChatGPT unsafe for marketing work?
This report does not show that. The administrator does not know why the message appeared and is not claiming OpenAI was compromised. The report does show that an instruction inside a trusted chat can still be a trap, so the rule about pasting commands applies to every AI tool.
What is ClickFix?
A social engineering technique where a fake verification or error message talks you into pasting a command into the Windows Run box or a terminal. You run the attack yourself. Microsoft and Proofpoint have both published about it.
What should I do if an AI tool tells me to paste a command into Windows?
Do not paste it. Close the page and tell the person who handles your IT. If you already pasted it, tell them right away.
Do we need a formal AI policy?
A single page is enough to start: which tools are approved, what files may go in, the paste rule, and who to call.