No legitimate CAPTCHA should ask you to copy code into Windows Run, PowerShell, or Terminal. In a campaign reported by TechRadar Pro on September 30, 2026, attackers used a custom GPT called “Plus 5.6” to direct visitors away from chatgpt.com to a fake verification page that could lead them to install malware. If you see this, stop: don’t run the command or download anything.
How the fake “Plus 5.6” ChatGPT link works
The campaign begins with a custom GPT hosted on the legitimate chatgpt.com domain. Its name, “Plus 5.6,” and its message are designed to look like a ChatGPT-related offer or service notice. The GPT claims the main service is unavailable and points visitors to a supposed backup.
That backup is hosted on Google Sites, not an OpenAI domain. It displays a fake Cloudflare CAPTCHA and tells visitors to copy and paste code into Windows Run. This is a form of ClickFix: instead of exploiting a vulnerability automatically, the attacker persuades the victim to run a command themselves. TechRadar Pro reported the campaign on September 30, 2026.
A link opening on chatgpt.com does not make every instruction or destination it presents safe. A custom GPT can be used as a lure, and a page hosted by a familiar provider is not necessarily operated by that provider or by OpenAI.
#1 Best Overall
- Military-Grade Security & Compliance: FIPS 140-2 Level 3 Certified with AES 256-bit hardware encryption for top-tier data protection, meeting strict standards like GDPR, HIPAA, SOX, and TAA compliance.
- Ultra-Fast USB 3.0 Performance: SuperSpeed USB 3.0 (USB 3.2 Gen 1x1) delivers high-speed data transfers, available in storage capacities up to 512GB, ideal for large files.
- Comprehensive Protection: Built-in tamper-resistant design with Award-Winning Bitdefender antivirus to protect against malware, plus remote management capabilities for added control.
- Remote Management Capabilities: Compatible with Kanguru Remote Management Console (KRMC-Hosted) for remote monitoring, security policy enforcement, and device tracking.
- Rugged & Tamper-Resistant Design: Waterproof, tamper-proof alloy casing with secure firmware to prevent "BadUSB" attacks, built to withstand harsh conditions.
Signs a ChatGPT link or verification page is a trap
- It says ChatGPT is unavailable, then redirects you. Be suspicious when a GPT or message claims the primary service is down and sends you to a different host for access or verification.
- The “backup” uses an unrelated domain. A Google Sites page is not an official OpenAI site just because it mentions ChatGPT or uses familiar branding.
- The CAPTCHA asks you to run something. A human-verification screen should not require you to paste code into Windows Run, PowerShell, or Terminal. Do not follow those instructions.
- It offers an installer, browser extension, or update outside the official app or website. Don’t install software from a page reached through an unexpected redirect.
- It creates urgency or asks for payment or credentials. Treat a deadline, payment demand, or lookalike sign-in prompt as a reason to stop and verify independently.
What to do if you encounter the scam
- Stop interacting with the page. Don’t copy, paste, or run its command; don’t download its installer; and don’t enter payment details or account credentials.
- Close the tab. Don’t use a phone number or another link displayed on the suspicious page.
- Check the claim independently. Open the official OpenAI app or type the official website address yourself. OpenAI Academy advises: “Never click a suspicious link or call a number included in the message. Verify the claim independently through an official app, website, phone number, or someone you trust.”
- Use browser protection as one layer. Microsoft’s June 2026 guidance recommends browsers that support Defender SmartScreen, which can identify and block malicious, phishing, and scam sites, as well as sites hosting malware. Browser warnings are useful, but they are not a substitute for refusing to run an unexpected command.
If you already pasted or ran the CAPTCHA command
If you ran the command, treat the device as potentially compromised. Don’t enter more passwords or payment details on it while you respond. Where practical, disconnect it from accounts containing sensitive information and use a clean device for account recovery.
- Run a reputable malware scan and follow its instructions for quarantining or removing detections.
- Update the operating system and browser.
- If you entered credentials, change the affected passwords from a clean device and enable multifactor authentication. Change reused passwords on other accounts, too.
- Check for browser extensions you don’t recognize, unexpected processes, unusual camera or microphone activity, and account-security alerts.
- If suspicious activity continues or you can’t confidently remove it, get professional incident-response help.
These steps reduce risk but cannot establish by themselves that a device is clean. If important work or sensitive accounts are involved, ask a qualified professional to assess it.
Rank #2
- 【Wide Application for Data Security】These USB‑A port locks are widely used in commercial, office, educational, public, medical, and household environments, providing comprehensive data security. They effectively prevent unauthorized access to USB ports and protect sensitive information.
- 【Perfect Fit for USB‑A Ports】Specially designed for standard USB‑A ports, these locks fit securely on PCs, laptops, and tablets. The tight and stable fit ensures reliable protection without loosening or falling out. Easy to Lock and Remove
- 【Easy to Lock and Remove】These USB port locks can only be removed with the included keys, balancing security and convenience. Installation and removal are simple and tool‑free, making daily management easy.
- 【Dual Protection】: Security & Dustproof Provides physical security to block unauthorized USB connections, while preventing dust, dirt, and moisture from entering ports. This dual protection enhances data safety and extends the service life of devices.
- 【Multiple Colors and Quantities Available】These USB‑A port locks are available in two colors and various quantities to meet different color‑coding and organization needs
How to choose protection against scam links and malware
Protection works best in layers. When comparing security tools or deciding what you still need, look at what each one actually does:
| Protection area | What to check | What it does not replace |
|---|---|---|
| Blocking before execution | Whether the browser or security tool can warn about malicious links and downloads before you open or run them. Microsoft says Defender SmartScreen can help identify and block malicious, phishing, and scam sites and sites hosting malware. | Your judgment about an instruction to run code. A page that loads is not proof that it is safe. |
| Scanning after a file or command is encountered | Whether the tool scans for malware and supports removal or quarantine. | Prevention: a scan is not a reason to run an unfamiliar command or install an unexpected file. |
| Independent checking and reporting | Whether you can verify an alert through an official app or website and report suspicious content. Malwarebytes documents Scam Guard in ChatGPT as a way to assess risk, spot scams faster, and report suspicious content. | A guarantee that a message or page is safe. OpenAI Academy warns that ChatGPT can help notice warning signs but cannot guarantee a message is safe. |
| Account protection | Whether important accounts have multifactor authentication and unique passwords, and whether you can review security alerts. | Device cleanup if malware may already have run. |
Why this scam fits a wider pattern
The fake custom GPT is one example of attackers borrowing familiar AI brands to make deceptive pages or downloads seem trustworthy. Microsoft’s June 2026 research describes attackers rotating popular AI brands into phishing and malware-download campaigns. OpenAI’s October 1, 2025 report described scam networks using ChatGPT for scripts, impersonation, and victim engagement; its July 31, 2026 case study described a Cambodia-based operation using ChatGPT in investment, romance, gambling, and impersonation scams, including urgent requests and promises of guaranteed or risk-free returns.
Rank #3
- Protect Your Data: Blocks all data lines while allowing full-speed charging—perfect for defending against juice jacking and unauthorized data access in public places.
- Travel-Ready Security: Compact corded design fits easily in your bag or pocket, offering essential data protection for airports, hotels, coffee shops, and shared workspaces.
- Universal Compatibility: Works seamlessly with USB-C charging setups, supporting smartphones, tablets, e-readers, and other USB-powered devices.
- Flexible Corded Design: Short inline cable reduces strain on ports and provides easy connectivity—even in tight or awkward charging spots.
- Easy Plug-and-Play: No apps, drivers, or setup required—just connect and charge securely with peace of mind.
A separate fake ChatGPT billing campaign reported by ITPro in September 2026 demanded $23.80 within 48 hours and used a non-OpenAI sender domain and a lookalike sign-in page. That demand was reported for that separate campaign; it is not evidence that every unexpected ChatGPT-related message has the same payment request. TechRadar Pro’s September 30 report did not establish a verified victim or infection count for the “Plus 5.6” campaign.
Quick Recap
Best Value
- 【Wide Application for Data Security】These USB‑A port locks are widely used in commercial, office, educational, public, medical, and household environments, providing comprehensive data security. They effectively prevent unauthorized access to USB ports and protect sensitive information.
- 【Perfect Fit for USB‑A Ports】Specially designed for standard USB‑A ports, these locks fit securely on PCs, laptops, and tablets. The tight and stable fit ensures reliable protection without loosening or falling out. Easy to Lock and Remove
- 【Easy to Lock and Remove】These USB port locks can only be removed with the included keys, balancing security and convenience. Installation and removal are simple and tool‑free, making daily management easy.
- 【Dual Protection】: Security & Dustproof Provides physical security to block unauthorized USB connections, while preventing dust, dirt, and moisture from entering ports. This dual protection enhances data safety and extends the service life of devices.
- 【Multiple Colors and Quantities Available】These USB‑A port locks are available in two colors and various quantities to meet different color‑coding and organization needs
Rank #4
- 【Wide Application for Data Security】These USB‑A port locks are widely used in commercial, office, educational, public, medical, and household environments, providing comprehensive data security. They effectively prevent unauthorized access to USB ports and protect sensitive information.
- 【Perfect Fit for USB‑A Ports】Specially designed for standard USB‑A ports, these locks fit securely on PCs, laptops, and tablets. The tight and stable fit ensures reliable protection without loosening or falling out. Easy to Lock and Remove
- 【Easy to Lock and Remove】These USB port locks can only be removed with the included keys, balancing security and convenience. Installation and removal are simple and tool‑free, making daily management easy.
- 【Dual Protection】: Security & Dustproof Provides physical security to block unauthorized USB connections, while preventing dust, dirt, and moisture from entering ports. This dual protection enhances data safety and extends the service life of devices.
- 【Multiple Colors and Quantities Available】These USB‑A port locks are available in two colors and various quantities to meet different color‑coding and organization needs
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

