You’ve seen them countless times: “Tick the box to prove you’re not a robot.”

CAPTCHAs have become such a normal part of using the internet that most people complete them without giving them much thought. A quick click, perhaps selecting a few images, and then moving on.

Unfortunately, cybercriminals are now using that familiarity against us.

A growing number of fake CAPTCHA scams are appearing online. These pages are designed to look legitimate and rely on users following instructions without stopping to question them. Instead of asking you to click a checkbox or identify images, these fake verification pages ask you to confirm you’re human by sending a text message.

At first glance, it may seem like a harmless extra step. The page appears genuine, and the process feels similar to other online verification methods.

Typically, the scam works like this:

  • You visit what appears to be a legitimate website or online service.
  • A CAPTCHA-style verification page appears.
  • You’re prompted to send a pre-written text message.
  • Your phone automatically opens a new SMS with the recipient and message already filled in.
  • All that’s left to do is press “Send”.

The process seems simple enough. However, behind the scenes, sending that message can trigger multiple SMS messages to international or premium-rate numbers. In some cases:

  • Several messages may be sent without the user fully understanding what’s happening.
  • Small charges can be added each time.
  • Costs may continue accumulating before they’re noticed.

One of the reasons this scam is so effective is that the charges often don’t appear immediately. By the time the additional costs show up on a mobile bill, the original “verification” process has usually been forgotten. Many users never make the connection.

There is another concern as well. These fake CAPTCHA pages don’t always appear randomly. Users can be redirected to them through:

  • Compromised websites
  • Malicious online advertisements
  • Unsafe advertising networks
  • Suspicious links that look legitimate

Everything about the experience is designed to feel familiar and trustworthy. In some cases, the browser behaviour may even encourage users to continue, making it less obvious how to exit the page and return to safety.

What makes this threat particularly dangerous is that it doesn’t depend on advanced hacking techniques. Instead, it relies on habit. People are used to seeing CAPTCHAs and generally trust them. When something looks routine, most users complete the task quickly and move on.

That’s exactly what cybercriminals are counting on.

How to Stay Safe

Remember this simple rule: A legitimate CAPTCHA should never ask you to send a text message.

If you encounter a CAPTCHA that requests an SMS verification:

  • Stop immediately.
  • Do not send the message.
  • Close the page.
  • Avoid interacting with any prompts or buttons.
  • Report the incident to your IT team if you’re at work.

It’s also worth reminding employees about this tactic as part of regular cybersecurity awareness training. A few minutes of education can prevent unnecessary costs, confusion, and potentially more serious security issues later on.

As with many cyber threats, awareness is one of the most effective forms of defence.

If you’d like help improving cybersecurity awareness across your organisation or strengthening your business’s overall IT security, contact us today. Our team can help you identify risks, educate your staff, and build stronger protection against emerging online threats.


Give us a call  ‣  031 818 9060