Fake CAPTCHA scams are becoming a clever way for cybercriminals to trick people into installing malware, revealing sensitive information, or allowing unwanted activity on their devices.
A CAPTCHA is normally used by legitimate websites to determine whether a visitor is a human rather than an automated program. However, scammers can create fake “I’m Not a Robot” verification pages that look convincing and use them as part of phishing or malware campaigns.
In June 2026, the Federal Trade Commission (FTC) warned about a CAPTCHA scam in which victims were instructed to press keyboard shortcuts and paste commands into their computers. Instead of verifying that the visitor was human, these instructions could cause malicious software to run on the device.
This guide explains how fake CAPTCHA scams work, the warning signs to watch for, and what you should do if you accidentally interacted with one.
What Is a CAPTCHA?
CAPTCHA stands for “Completely Automated Public Turing test to tell Computers and Humans Apart.”
You may have encountered CAPTCHAs when logging into an account, creating an account, submitting a form, or accessing certain websites.
A legitimate CAPTCHA may ask you to:
- Select images containing cars, traffic lights, or bicycles.
- Type characters displayed in an image.
- Confirm that you are not a robot.
- Complete a simple verification challenge.
The purpose is generally to distinguish human visitors from automated bots.
The problem is that scammers can imitate the appearance of legitimate CAPTCHA systems.
What Is a Fake CAPTCHA Scam?
A fake CAPTCHA scam uses a fraudulent verification page to persuade you to perform an action that a genuine CAPTCHA would not require.
For example, a suspicious page may display an “I’m Not a Robot” box and then tell you to press Windows + R, paste something, and press Enter.
That is a major warning sign.
According to the FTC, legitimate CAPTCHA systems do not require users to run commands on their computers. Following instructions that cause commands to execute can instead install malware capable of stealing information such as email credentials and banking details.
How Fake CAPTCHA Scams Work
Fake CAPTCHA attacks can follow several stages.
1. You Visit a Compromised or Suspicious Website
The scam may begin when you visit a website containing malicious advertising, a compromised page, a suspicious download, or an unsafe link.
You may suddenly be redirected to a page claiming that you need to complete a security verification.
2. A Fake “I’m Not a Robot” Message Appears
The page may imitate a familiar CAPTCHA design.
It might say:
“Verify you are human.”
or:
“Security verification required.”
The appearance is designed to make the request seem routine.
3. The Page Gives Unusual Instructions
This is where the scam becomes particularly dangerous.
Instead of simply asking you to select pictures or complete a normal CAPTCHA, the page may instruct you to:
- Press Windows + R.
- Open a command window.
- Copy and paste text.
- Open PowerShell or another system utility.
- Paste a command.
- Download an unknown file.
- Disable security software.
- Install an unfamiliar application.
Do not follow these instructions.
A CAPTCHA should not require you to execute commands on your computer.
4. Malware May Be Installed
If you execute the attacker’s instructions, malicious software may be downloaded or executed.
Depending on the malware involved, criminals may attempt to steal passwords, browser information, financial credentials, session data, or other sensitive information.
5. Your Accounts Could Be Targeted
If malware obtains information stored on your device, attackers may attempt to access email, social media, shopping, cryptocurrency, or financial accounts.
This is one reason fake CAPTCHA scams should be treated as a security issue rather than simply an annoying pop-up.
Warning Signs of a Fake CAPTCHA
Watch for these red flags.
It Tells You to Run a Command
This is one of the biggest warning signs.
A genuine CAPTCHA should not ask you to open Windows Run, Command Prompt, PowerShell, Terminal, or another system tool.
It Asks You to Copy and Paste Unknown Text
Never blindly copy commands from a webpage into your computer’s command line.
Even if the page claims the command is necessary for verification, treat the request as suspicious.
It Creates a Sense of Urgency
Scammers may claim that:
- Your browser is at risk.
- Your account will be blocked.
- You must verify immediately.
- Your device has been detected as suspicious.
- The verification will expire shortly.
Urgency is commonly used to discourage people from thinking carefully.
The Page Redirects You Unexpectedly
If you were browsing one website and suddenly landed on an unfamiliar CAPTCHA page, close it rather than automatically following its instructions.
It Requests a Download
Be especially cautious if a CAPTCHA asks you to download an application, browser extension, executable file, or other software.
The Website Address Looks Suspicious
Check the domain name carefully.
Scammers can create websites with names that resemble legitimate services. The FBI recommends carefully examining URLs and watching for subtle differences in addresses used in phishing schemes.
Fake CAPTCHA vs. Legitimate CAPTCHA
| Legitimate CAPTCHA | Fake CAPTCHA Scam |
|---|---|
| May ask you to identify images | May ask you to run commands |
| May ask you to type characters | May ask you to paste unknown text |
| Usually stays within the webpage | May instruct you to open system utilities |
| Does not require installing unknown software | May request downloads |
| Does not normally require command-line instructions | May use Windows Run, PowerShell, or Terminal |
| Designed to verify that you are human | Designed to trick you into performing a dangerous action |
What Should You Do If You See a Suspicious CAPTCHA?
The safest approach is simple: do not interact with the suspicious instructions.
- Do not copy or paste commands.
- Do not press Windows + R because the page told you to.
- Do not download unfamiliar software.
- Do not disable your antivirus or security features.
- Close the suspicious webpage.
- Update your browser and operating system.
- Run a security scan if you believe you interacted with the page.
- Change important passwords if you believe your information may have been exposed.
Google provides guidance for removing unwanted pop-ups, ads, and malware from Chrome, including checking for unwanted software and reviewing browser settings.
What If You Already Followed the Instructions?
Don’t panic, but act quickly.
If you pasted a command or downloaded something after following a fake CAPTCHA, disconnect the affected device from the internet if you suspect malware was installed.
The FTC recommends running a security scan, keeping software updated, changing passwords, and enabling two-factor authentication from a different device if malware may have accessed your accounts.
1. Disconnect From the Internet
Temporarily disconnect the affected device from Wi-Fi or wired internet.
This can help limit communication between malware and remote systems while you investigate the problem.
2. Run a Security Scan
Use a reputable security product to perform a full scan.
For Windows users, Microsoft recommends running a full scan with Windows Security when dealing with suspected malware or tech-support-related threats.
3. Change Your Passwords
If you suspect that passwords may have been exposed, change them from a clean device.
Prioritize important accounts such as:
- Online banking
- Social media
- Shopping accounts
- Cloud storage
- Cryptocurrency accounts
Use unique passwords and enable two-factor authentication wherever available.
4. Contact Your Bank If Financial Information Was Exposed
If you entered banking information, payment details, or other financial information after interacting with the scam, contact your financial institution as soon as possible.
Monitor your accounts for transactions you do not recognize.
5. Report the Scam
For U.S. readers, suspicious CAPTCHA scams can be reported to the FTC through ReportFraud.ftc.gov. The FTC specifically recommends reporting fake CAPTCHA pages that attempt to distribute malware.
Online scams can also be reported to the FBI’s Internet Crime Complaint Center (IC3) at IC3.gov.
How to Protect Yourself From Fake CAPTCHA Scams
You can significantly reduce your risk by developing a few safe browsing habits.
Never Run Commands Provided by a Random Website
This is perhaps the most important rule.
If a webpage tells you to open Command Prompt, PowerShell, Windows Run, Terminal, or another system tool and paste something into it, stop.
Keep Your Software Updated
Install security and browser updates when they become available.
Updates can address security vulnerabilities that criminals may attempt to exploit.
Use Security Software
Keep reputable antivirus or security protection enabled and updated.
Be Careful With Unknown Websites
Avoid downloading software, browser extensions, or files from unfamiliar websites.
Check the URL
Before entering sensitive information, examine the website address carefully.
A familiar-looking page does not necessarily mean the website is legitimate.
Don’t Trust Pop-Ups Automatically
A page can display professional-looking logos, security messages, warning banners, and verification screens without being legitimate.
Microsoft similarly warns that malicious websites can display convincing fake warnings and other messages designed to frighten users into taking unsafe actions.
Are Fake CAPTCHA Scams the Same as Phishing?
They can be considered a form of phishing or social engineering when criminals use a fake verification page to manipulate users into performing a harmful action or revealing information.
Traditional phishing often attempts to steal credentials directly. Fake CAPTCHA scams can instead manipulate the victim into executing malicious instructions themselves.
This makes the scam particularly deceptive because the victim may believe they are completing a normal security check.
Can a Fake CAPTCHA Infect Your Phone?
Fake CAPTCHA scams can target different devices, although the specific technique may differ between computers and mobile devices.
On a smartphone, suspicious pages may attempt to:
- Redirect you to malicious websites.
- Trick you into downloading an unsafe application.
- Obtain sensitive information.
- Encourage you to grant unwanted permissions.
- Push deceptive browser notifications.
Don’t install an application simply because a webpage claims it is necessary to complete a CAPTCHA.
Frequently Asked Questions
Is every “I’m Not a Robot” CAPTCHA a scam?
No. CAPTCHAs are widely used by legitimate websites. The warning signs are unusual instructions, suspicious redirects, unknown downloads, and requests to execute commands.
Can a CAPTCHA install malware?
A normal CAPTCHA is not supposed to require you to execute commands or install unknown software. Fake CAPTCHA pages can use social engineering to trick users into running malicious commands or downloading malware.
Should I press Windows + R when a CAPTCHA tells me to?
No. A legitimate CAPTCHA should not require you to open Windows Run and paste commands.
What if I only opened the fake CAPTCHA page?
Simply opening a suspicious webpage does not necessarily mean your device has been infected. Close the page and avoid interacting with its instructions. If you downloaded something or executed a command, perform a security scan and take additional precautions.
What should I do if I entered my password?
Change the affected password immediately from a trusted device. If you reused that password elsewhere, change it on those accounts as well. Enable two-factor authentication where available.
How can I report a fake CAPTCHA scam?
U.S. users can report scams to the FTC through ReportFraud.ftc.gov. Suspected internet crimes can also be reported through FBI IC3.
Final Thoughts
Fake CAPTCHA and “I’m Not a Robot” scams take advantage of something people see every day online: security verification.
The most important thing to remember is that a legitimate CAPTCHA should not require you to execute commands, paste unknown instructions into your computer, disable security software, or install unfamiliar programs.
If a CAPTCHA suddenly asks you to perform unusual computer operations, stop and close the page.
When in doubt, don’t follow instructions provided by the suspicious webpage. Visit the legitimate website directly instead of relying on a pop-up or unexpected redirect.
Related Security Guides
- Back-to-School Scams 2026
- Back-to-School Scams 2026: Fake Scholarships, Grants & Laptops
- Back-to-School Shopping Scams
- Fake Student Grant Scams: Warning Signs to Watch For
- Fake Apple Support Scams: How to Spot and Avoid Them
- Fake Apple Support Scam
Helpful Official Resources
- FTC Consumer Advice: How to Spot a CAPTCHA Scam
- FTC Scam Information
- Google Chrome Help: Remove Unwanted Ads, Pop-Ups & Malware
- Microsoft: Protect Yourself From Tech Support Scams
- FBI: Spoofing and Phishing
Note: This article focuses on consumer education, scam prevention, cybersecurity awareness, and safe browsing practices. It does not promote hacking, malware, illegal activity, or unsafe software.
