Warning: Don’t Fall for Fake CAPTCHAs
Your team has seen hundreds of CAPTCHAs. “Click here to prove you’re not a robot.” It’s routine; nobody thinks about it twice. That familiarity is exactly what makes the fake CAPTCHA scam so effective.
A growing number of fraudulent CAPTCHA pages now ask users to “confirm they’re human” by sending a text message rather than clicking a box. The page looks completely normal. You tap a button, your phone opens a pre-written message, and you press send.
Simple. Except that single action can trigger dozens of texts to international premium-rate numbers.
Why the Bill Arrives Weeks Later
Each message adds a small charge. Because those charges don’t appear immediately, the connection isn’t obvious. By the time your firm’s phone bill arrives, no one remembers the “verification” they completed.
That delay is what makes this scam particularly effective against busy offices, including law firms where phones and devices are constantly in use.
These fake pages don’t always appear randomly. Compromised websites and advertising networks can redirect users to them. The page feels familiar; the browser even nudges you forward, making it harder to simply exit.
The rule is simple: a real CAPTCHA never asks you to send a text message. If your team ever sees that request, they should stop, close the page, and not interact further.
Awareness is your first line of defense. If you’d like to make sure your firm’s team knows what to watch for, get in touch with Amicus IT.