Warning: Don’t Fall for Fake CAPTCHAs

Michael Tunstall

August 14, 2026

You've probably completed hundreds of CAPTCHAs without giving them much thought.

Tick a box.

Select a few traffic lights.

Confirm you're not a robot.

Then carry on with whatever you were doing.

They're so familiar that most of us instinctively follow the instructions without questioning them.

And cyber criminals are taking advantage of that.

Fake CAPTCHAs are becoming more convincing

A growing scam uses fake CAPTCHA pages to trick people into completing actions that have nothing to do with proving they're human.

One version asks you to verify yourself by sending a text message.

That should immediately seem unusual, but the page is designed to make it feel like part of a legitimate verification process.

You tap the button, your phone opens a pre-written message and you're simply asked to press send.

It takes seconds.

But what's actually happening behind the scenes can be very different.

One tap could result in unexpected charges

The scam can cause multiple messages to be sent to international or premium-rate numbers.

Individually, the charges may be relatively small.

But if multiple messages are generated, the cost can quickly add up.

There's another reason the scam can be difficult to spot: you may not notice the financial impact immediately.

The charges might not become obvious until your next mobile phone bill arrives.

By that point, the CAPTCHA you completed weeks earlier may be the last thing on your mind.

How do people end up on these pages?

Fake CAPTCHA pages don't necessarily arrive through an obviously suspicious email or message.

People can be redirected to them after visiting compromised websites, clicking online adverts or following links that initially appear legitimate.

The page they eventually reach looks familiar.

There's a verification request.

There are instructions to follow.

And because people have completed CAPTCHAs countless times before, their instinct is often to follow those instructions and move on.

That's exactly what makes the attack effective.

It exploits habit rather than technology

Many cyber attacks succeed because they imitate something people already trust.

Fake CAPTCHAs are a perfect example.

We're conditioned to expect verification checks when browsing websites, logging into accounts or accessing online services.

That familiarity means we're less likely to stop and question what's being requested.

But there's one very simple rule worth remembering:

A CAPTCHA should never require you to send a text message to prove you're human.

If you're presented with one that does, don't continue.

Close the page and avoid interacting with it any further.

Make sure your team knows what to look for

Cyber security awareness isn't about making employees suspicious of everything they see online.

It's about helping them recognise when something familiar starts behaving in an unfamiliar way.

If a CAPTCHA asks you to send a text, run a command, download something, copy and paste instructions or perform another unusual action, that's a good reason to stop.

Taking a few seconds to question an unexpected request can prevent a much bigger problem later.

As scams become more convincing, keeping employees informed about the latest tactics is an increasingly important part of protecting your business.

If you'd like help improving cyber security awareness across your organisation and making sure your team knows what to look out for, get in touch.

<All Posts