A fake CAPTCHA scam is catching out business users by exploiting one of the most familiar and trusted elements of everyday online activity. CAPTCHAs, the verification prompts that ask you to tick a box, select images, or solve a puzzle to confirm you are not a bot, are something most people encounter regularly and complete without much thought. That automatic trust is precisely what attackers are now using against them.
How the Fake CAPTCHA Scam Works
A standard CAPTCHA asks you to click a box or identify objects in images. The new scam presents a page that looks and feels like a routine CAPTCHA prompt but contains an unusual step: rather than clicking a checkbox, it asks you to prove you are human by sending a text message.
The page presents this as a verification method. The design is familiar enough that the request does not immediately raise alarm. You tap the button as instructed, your phone opens a pre-written text message, and a single further tap sends it. The action takes seconds and feels entirely routine in the moment.
What happens behind the scenes is different. That single tap can trigger multiple text messages being sent to international premium-rate numbers. Each message adds a charge to the phone bill. In some cases, the scam generates dozens of these charges from a single interaction. The charges do not appear immediately, so the connection between the CAPTCHA page and the bill is not obvious. A few weeks later, an unexpectedly high phone bill arrives, and by that point the source of the problem may not be remembered at all.
This delayed consequence is a deliberate feature of the scam rather than an accident. The gap between the action and the financial impact reduces the chance that anyone will connect the two events and report the incident promptly.
Why the Fake CAPTCHA Scam Is Effective
The effectiveness of this scam rests on habit rather than technical deception. CAPTCHAs are trusted because they are familiar. They are part of the routine friction of using the internet. When something looks like a CAPTCHA, the instinct is to complete it quickly and move on. That instinct, which in genuine CAPTCHA situations is entirely reasonable, is the mechanism the scam exploits.
The scam does not rely on persuading someone that something risky is safe. It relies on someone not noticing that something is different. The difference between a genuine CAPTCHA and a fake one that asks for a text message is meaningful, but it requires active attention to spot when the overall visual context is familiar and the action sequence feels routine.
Staff who are moving quickly between tasks, checking something on their phone while attending to other work, or simply proceeding through a page without reading each element carefully are in exactly the conditions the scam is designed for. Busy, familiar, and low-scrutiny. Our article on overconfident employees and cyber security risk covers how the sense that something is routine reduces the caution people apply, even among staff who are generally security-aware.
How Users Reach Fake CAPTCHA Pages
These fraudulent CAPTCHA pages do not always announce themselves through an obvious suspicious link. Staff can reach them through compromised websites, through advertising networks that have been infiltrated by malicious content, or through redirects that begin with a legitimate-looking click elsewhere on a page.
In some cases, the browser behaviour itself is engineered to make exit harder. The page may resist the back button, appear over the top of other content, or use design elements that make the path of least resistance look like completing the verification rather than closing the tab. This is not accidental. It is designed to prevent the moment of hesitation that would allow someone to think before tapping.
This approach connects to the broader pattern of attackers using familiar environments to reduce scrutiny. Our article on malvertising attacks covers how legitimate advertising networks and trusted websites are used as delivery mechanisms for harmful content, precisely because the associated credibility lowers the user’s guard.
The Single Rule That Prevents This Scam
The protection against this particular scam is simple and memorable, which makes it easy to communicate across a team.
A genuine CAPTCHA will never ask you to send a text message. This is a reliable and absolute rule. Standard CAPTCHA systems work through visual verification, checkbox interaction, audio challenges, or puzzle solving. None of them require the user’s phone to send an outbound message. A verification prompt that asks for this is not a CAPTCHA. It is a scam.
If any team member encounters a page asking them to tap to send a text as part of a verification, the correct response is to stop immediately, close the page or browser tab, and not interact with the prompt further. The phone number that would have received the message, and the charges that interaction would have triggered, never come into play.
Sharing this rule with your team takes only a moment. A brief message, a mention in a team meeting, or an addition to any existing security awareness guidance is sufficient. The rule is specific enough to be retained and broad enough to cover any variation of this type of scam that may appear in future. Our article on digital fraud protection covers the broader set of habits that protect business teams from scams that exploit everyday online behaviour.
Checking Phone Bills for Unexplained Charges
Because the charges from this scam do not appear immediately, a business may have been affected without yet knowing it. Premium-rate international text charges appearing on a phone bill without an obvious explanation are worth investigating, particularly if they correspond to a period when any team member was using their phone for routine web activity.
For businesses where staff use company phones or where phone bills pass through a finance or administration function, this is a worthwhile check to run periodically. Unexplained charges on any account are worth querying promptly with the relevant service provider, who may be able to identify the source and in some cases apply a block against further premium-rate text charges.
What This Means For Businesses
The fake CAPTCHA scam is a good illustration of how attackers increasingly rely on familiar contexts rather than technical complexity. The simpler the mechanism, the less scrutiny it receives. A verification prompt that looks routine will be completed by habit in a way that a suspicious email or an unusual download request would not.
For business owners and directors in Brighton and across Sussex, the practical response is brief but worthwhile. Communicate the CAPTCHA rule to your team. Explain that no legitimate verification system asks you to send a text message and that any prompt making this request should be closed immediately. Remind staff that the absence of an immediate consequence, no error message, no visible problem, does not mean the interaction was safe.
Our managed IT services include staff awareness support and security guidance for businesses across Sussex and the South East, helping teams stay informed about the specific scams actively targeting everyday online behaviour.
Final Thoughts
The fake CAPTCHA scam works because it asks nothing unusual of the people it targets. It simply places a harmful action inside a familiar-looking container and relies on habit to carry the rest. The defence is equally simple: know that CAPTCHAs do not ask for text messages, and stop when you see one that does.
Share this with your team today. It is one of those pieces of awareness that takes seconds to communicate and that, once known, makes the entire category of scam effectively harmless.
A fake CAPTCHA scam presents a fraudulent verification page designed to look like a standard CAPTCHA prompt. Instead of asking the user to tick a box or identify images, it asks them to prove they are human by sending a text message. That action sends messages to premium-rate international numbers, generating charges that appear on the phone bill weeks later.
A genuine CAPTCHA will never ask you to send a text message. Legitimate verification systems use visual challenges, checkbox interactions, audio options, or puzzle solving. If a page asks you to tap a button that opens a pre-written text message on your phone, it is a scam. Close the page immediately without tapping further.
Fake CAPTCHA pages can appear through compromised websites, malicious advertising networks, or redirects from pages that began with a legitimate-looking click. The browser may also resist exit attempts, using design choices that make completing the prompt feel like the easier path than closing the tab.
They should stop immediately and close the browser tab or page without tapping any button that would send a text message. They should report the incident to whoever manages IT in the business so the source can be identified and other team members can be warned. If they believe they may have already sent a text from such a prompt, they should report this to allow the phone account to be checked for unexplained charges.
The premium-rate charges generated by the scam do not appear on the phone bill immediately. They typically arrive weeks later, by which point the connection between the CAPTCHA interaction and the charges is not obvious. This delay is deliberate and reduces the chance that the incident is reported and investigated promptly.