top of page
Cache4-logo-transparent.png

Fake CAPTCHA Scams: Why “I’m Not a Robot” Could Put Your Business at Risk

Sep 17
4 min read

CAPTCHAs are so familiar that most of us barely think about them. Tick the box, identify a few traffic lights and carry on. That familiarity is exactly what makes a fake CAPTCHA dangerous.


Cyber criminals are using convincing “I’m not a robot” pages to persuade people to run malicious commands themselves. The page may look routine, but the instructions that follow are anything but.


The simple rule: a genuine CAPTCHA should never ask you to open Run, PowerShell or Terminal, or paste a command.

What is a fake CAPTCHA scam?


A fake CAPTCHA scam copies the look of a normal human-verification check. After you click the familiar checkbox, it claims that verification has failed or that an extra step is required. It then tells you to open a system tool such as Windows Run, PowerShell or Terminal and paste something from your clipboard.


That command can download malware, steal information or give an attacker access to the device. The important point is that the attacker is not exploiting the CAPTCHA itself. They are using a trusted-looking page to convince the user to run the attack for them.


How the fake CAPTCHA attack works


  1. You land on a compromised or malicious website that displays a familiar CAPTCHA-style verification page.

  2. The page says normal verification has failed or asks you to complete an additional step.

  3. A malicious command is copied to your clipboard, often without clearly showing you what it contains.

  4. You are told to open Windows Run, PowerShell, Terminal or another system tool and paste the command.

  5. When you press Enter, the command can download or run malware and compromise the device.


Six warning signs of a fake CAPTCHA


  • It asks you to do anything outside the browser.

  • It tells you to press Windows + R, open PowerShell, Command Prompt or Terminal.

  • It asks you to paste something from your clipboard.

  • It says verification failed and then gives unusual manual instructions.

  • It shows a command, verification ID or technical-looking text intended to make the process feel legitimate.

  • It pressures you to complete several steps before you can continue to the website.


Why are we warning businesses about this now?


This is an active attack technique, often referred to as ClickFix. In August 2026, Microsoft Threat Intelligence reported a TerminalFix campaign that used compromised websites and fake Cloudflare CAPTCHA overlays to trick users into copying and running malicious PowerShell commands.


The wider use of CAPTCHA-style lures has also grown sharply. Microsoft’s Q1 2026 email threat report reported that CAPTCHA-gated phishing volumes reached 11.9 million attacks in March 2026, more than double the previous month. Not every CAPTCHA-gated phishing attack is the same as a fake CAPTCHA ClickFix attack, but it shows how heavily criminals are leaning on familiar verification experiences to lower people’s guard.


What should staff do if they see one?


  • Do not follow any instructions that take you outside the browser.

  • Do not paste or run a command copied from a website.

  • If it is safe to do so, take a screenshot of the page and note the website address.

  • Close the page.

  • Report it to your IT provider or internal IT contact so they can investigate and, where appropriate, block the site.


What if someone has already run the command?


Treat it as a potential security incident rather than waiting to see whether anything unusual happens.


  • Disconnect the device from Wi-Fi or the wired network.

  • Stop using the device.

  • Contact your IT provider immediately and explain exactly what happened.

  • Do not try to remove the malware or undo the command yourself unless your IT team asks you to.


The quicker the device can be isolated and investigated, the better the chance of limiting what an attacker can access.


What can a small business do to reduce the risk?


There is no single security product that removes every social-engineering risk. The best defence is a combination of sensible technical controls and staff who know when something does not look right.


  • Give staff simple, regular security-awareness guidance using real examples.

  • Use appropriate endpoint security and monitoring on business devices.

  • Limit unnecessary administrative privileges so one mistaken command cannot automatically do everything.

  • Make it easy for staff to report something suspicious without worrying that they will be blamed for asking.

  • Have a clear response process so people know who to call if they think they have made a mistake.


This is part of the approach we take with small-business cyber security at Cache4: appropriate protection around the technology, backed up by straightforward guidance that people can actually use.


One rule worth sharing with your whole team


If a website asks you to open a system tool or run a command to prove you are human, stop.

A genuine CAPTCHA should stay inside the browser. If you are unsure, close the page and ask your IT provider before doing anything else.


Share the Fake CAPTCHA Security Bulletin with your team


We have also created a simple Fake CAPTCHA Security Bulletin that businesses can share with staff. It shows the warning signs at a glance, what to do when a suspicious verification page appears, and what to do immediately if someone has already run the command.


The downloadable bulletin will be added here before this article is published.



Comments


bottom of page