Most people have seen a CAPTCHA hundreds of times.
You tick a box, select a few images, prove you are not a robot, and move on.
It has become such a routine part of using the internet that most of us barely think about it anymore.
That familiarity is exactly what scammers are now exploiting.
A growing number of fraudulent websites are using fake CAPTCHA pages to trick people into completing actions that seem unusual, but not unusual enough to immediately raise suspicion.
Instead of asking users to click a checkbox or identify images, these fake verification pages ask them to confirm they are human by sending a text message.
At first glance, it can appear to be part of a legitimate verification process.
The page presents a button, opens a pre-written text message on the user’s phone, and instructs them to press send.
It feels simple and harmless.
Unfortunately, that is where the problem begins.
Behind the scenes, that single action can trigger multiple text messages to premium-rate or international numbers. In some cases, dozens of messages may be sent.
Each one generates a charge.
Because those charges often do not appear immediately, victims rarely connect the eventual bill with the verification process they completed days or even weeks earlier.
That delay is one of the reasons this scam can be so effective.
There is another factor that makes these attacks convincing.
Many of these fake CAPTCHA pages are not found on obviously suspicious websites. Users can be redirected to them through compromised websites, malicious advertising networks, or misleading links.
A person clicks on something that appears legitimate, lands on a page that feels familiar, and follows the instructions without questioning them.
Some pages are even designed to make it difficult to navigate away, creating just enough pressure to encourage users to continue.
What makes this threat particularly important is that it does not rely on technical vulnerabilities.
It relies on habit.
People encounter CAPTCHAs so often that they rarely stop to evaluate them. When a process feels routine, decisions are made quickly.
That is exactly what attackers are counting on.
Fortunately, there is a simple rule that can help protect against this scam:
A legitimate CAPTCHA should never require you to send a text message to verify that you are human.
If a CAPTCHA asks you to send a text, stop immediately. Close the page and do not interact with it further.
It is also worth sharing this guidance with employees, especially as these scams become more common. Awareness remains one of the most effective ways to prevent security incidents before they happen.
Many cyberattacks succeed not because they are technically sophisticated, but because they take advantage of familiar routines.
A few seconds of caution can prevent unnecessary charges, frustration, and potential security risks later.
If someone on your team encountered a CAPTCHA asking them to send a text message, would they recognize it as a scam or assume it was a normal part of the verification process?

