A CAPTCHA is something most internet users have encountered while visiting websites. You may see an “I’m Not a Robot” checkbox or another human-verification challenge before accessing a page.
While legitimate CAPTCHA systems are designed to help websites distinguish people from automated bots, scammers are increasingly abusing the familiar appearance of CAPTCHA pages to trick people into performing unsafe actions.
In 2026, Microsoft has reported ongoing ClickFix-style campaigns involving fake CAPTCHA pages. On August 28, 2026, Microsoft documented a campaign called TerminalFix in which compromised websites displayed fake Cloudflare verification pages and attempted to persuade visitors to copy and execute a PowerShell command.
The important rule to remember is simple:
A website should not ask you to open Windows Run, PowerShell, Terminal, or paste an unknown command simply to prove that you are human.
What Is a Fake CAPTCHA Scam?
A fake CAPTCHA scam is a social-engineering scheme that uses a fraudulent human-verification page to persuade users to perform an unsafe action.
Legitimate CAPTCHA services can ask you to click a checkbox, select images, solve a challenge, or complete another verification step. Google’s official reCAPTCHA guidance explains that users may be asked to click a checkbox or complete an on-screen challenge.
A suspicious CAPTCHA page, however, may instruct you to:
- Press Windows + R
- Open PowerShell or Windows Terminal
- Copy and paste an unknown command
- Press Enter after pasting a command
- Install unfamiliar software
- Install an unknown browser extension
- Disable security protections
- Allow unexpected browser permissions
Those instructions should immediately make you cautious.
How the Fake “I’m Not a Robot” Scam Works
The exact technique can vary, but a typical scam may follow this pattern.
1. You visit a website
You could arrive at the page through a search engine result, advertisement, email, social-media post, redirect, or another website.
The website may initially look legitimate.
2. A verification screen appears
You may see a message such as:
“Verify you are human”
or
“I’m Not a Robot.”
Scammers may copy the appearance of familiar security services to make the page seem trustworthy.
3. You interact with the fake verification
After clicking the apparent verification box, the page may display additional instructions.
This is where the scam becomes more obvious.
4. You are told to perform an unusual computer action
The page might instruct you to open Windows Run, PowerShell, or Terminal.
This is a major warning sign.
Microsoft’s description of Trojan:HTML/FakeCaptcha explains that this type of social-engineering attack attempts to persuade users to copy and paste malicious PowerShell code into Windows Terminal.
5. You are encouraged to execute something
The attacker is attempting to persuade you to perform an action that could allow unwanted software or commands to run on your device.
This is different from simply completing a CAPTCHA inside your browser.
Why Are Fake CAPTCHA Scams So Convincing?
The technique works because CAPTCHA is already familiar to millions of internet users.
When people see a security-themed page, they may assume the instructions are part of the normal verification process.
Scammers can make fraudulent pages look convincing by copying elements such as:
- Verification checkboxes
- Security messages
- Familiar logos
- Loading animations
- Browser-style warnings
- Human-verification language
Microsoft says ClickFix has become a growing social-engineering technique, with attackers using fake error messages, fake verification pages and other convincing prompts to persuade users to execute commands.
Important: Not Every CAPTCHA Is Fake
It is important not to confuse legitimate CAPTCHA services with scams.
Google’s official reCAPTCHA documentation says a normal reCAPTCHA may ask you to click a checkbox or complete a challenge displayed on the webpage.
Cloudflare also operates legitimate security challenges designed to determine whether website visitors are human or automated traffic. Its current documentation explains that Cloudflare challenges can perform browser-based checks or ask visitors to take minimal actions such as checking a box or selecting a button.
Therefore, the presence of a CAPTCHA does not automatically mean that a website is fraudulent.
The concern is what the page asks you to do after or alongside the verification.
Warning Signs of a Fake CAPTCHA
1. It tells you to press Windows + R
Be extremely cautious if a verification page instructs you to open the Windows Run dialog.
A normal CAPTCHA does not need you to execute commands on your computer.
2. It tells you to open PowerShell or Terminal
This is another major red flag.
Microsoft has specifically documented fake CAPTCHA attacks that attempt to persuade users to execute commands through Windows Terminal or PowerShell.
3. It asks you to copy and paste a command
Never paste an unknown command into a terminal simply because a webpage tells you to.
If you don’t understand what a command does, don’t run it.
4. It creates unnecessary urgency
Be cautious when a page claims:
- “Your verification has failed.”
- “Complete this step immediately.”
- “Your browser is at risk.”
- “Security verification required.”
- “You must complete this step to continue.”
Urgent language can encourage users to act before thinking carefully.
5. It asks you to install software
A CAPTCHA should not normally require you to download an unfamiliar program just to prove that you are human.
6. It asks you to install a browser extension
Be careful if a supposed verification page tells you that you must install an unfamiliar extension before continuing.
7. It asks you to disable security features
Never disable antivirus protection or browser security simply because an unfamiliar webpage tells you to.
What Can Happen If You Follow Suspicious CAPTCHA Instructions?
The consequences depend on the particular campaign.
Possible risks include:
Unwanted software
A malicious command may attempt to download or launch unwanted software.
Account credential exposure
Some campaigns are designed to steal information such as browser-stored credentials or authentication data.
Privacy risks
Malicious software can potentially collect information from an affected device.
Further security problems
Once unwanted software has been installed, attackers may attempt additional actions against the affected device or accounts.
Microsoft’s research has documented ClickFix campaigns associated with information-stealing malware and other malicious activity.
What Should You Do When You See a Suspicious CAPTCHA?
If a CAPTCHA asks you to run a command, stop.
Follow these safer steps:
- Do not copy the command.
- Do not paste anything into PowerShell or Terminal.
- Do not press Windows + R because the webpage instructed you to.
- Close the suspicious browser tab.
- Avoid downloading unfamiliar software.
- Keep your browser and operating system updated.
- Run a security scan if you interacted with the suspicious page.
- If you entered sensitive information, consider changing the affected password from a trusted device.
- Monitor important accounts for unusual activity.
What If You Already Followed the Instructions?
If you accidentally followed suspicious instructions, don’t panic.
Take reasonable precautionary steps.
Run a security scan
Use your device’s reputable security software and perform an appropriate scan.
Microsoft provides information about its detection of Trojan:HTML/FakeCaptcha and related threats through its Malware Encyclopedia.
Microsoft Security – FakeCaptcha information
Change important passwords if necessary
If you entered a password or other sensitive information after interacting with a suspicious page, consider changing it from a trusted device.
Prioritize important accounts such as:
- Banking
- Payment services
- Social media
- Cloud storage
Enable two-factor authentication
Multifactor authentication can provide an additional layer of protection for supported accounts.
Contact your financial institution if you notice suspicious activity
If you see an unauthorized transaction, contact your bank or payment provider through its official website or customer-service channel.
How to Stay Safe From Fake CAPTCHA Scams in 2026
You don’t need advanced technical knowledge to avoid most fake CAPTCHA tricks.
Remember these basic rules:
- Keep your browser updated.
- Keep your operating system updated.
- Use reputable security software.
- Be cautious with unfamiliar websites.
- Avoid suspicious downloads.
- Check website addresses before entering sensitive information.
- Don’t blindly follow instructions displayed by unexpected pop-ups.
- Never paste unknown commands into PowerShell or Terminal.
- Don’t install unfamiliar browser extensions.
- Use strong, unique passwords.
- Enable multifactor authentication where available.
Microsoft’s recent 2026 threat research shows that CAPTCHA-based social engineering continues to evolve, making it particularly important for users to recognize suspicious instructions rather than relying solely on how professional a webpage looks.
Legitimate CAPTCHA vs. Fake CAPTCHA
| Legitimate CAPTCHA | Suspicious CAPTCHA |
|---|---|
| Verifies that you are human | Uses verification as a social-engineering trick |
| Usually operates within the webpage | May tell you to perform actions outside the browser |
| May use a checkbox or visual challenge | May instruct you to execute commands |
| Does not normally require PowerShell | May tell you to open PowerShell |
| Does not normally require Windows Run | May instruct you to press Windows + R |
| Provides an on-screen verification challenge | May ask you to copy and paste unknown commands |
Frequently Asked Questions
Is every “I’m Not a Robot” CAPTCHA a scam?
No. Legitimate websites use CAPTCHA and other human-verification technologies.
The warning sign is when the supposed CAPTCHA asks you to perform unusual actions, particularly running commands or installing unfamiliar software.
Can a fake CAPTCHA infect my computer?
It can be used as part of an attack designed to deliver unwanted or malicious software. Microsoft has documented fake CAPTCHA campaigns that attempt to persuade users to execute malicious PowerShell commands.
Does a legitimate CAPTCHA require Windows + R?
A standard CAPTCHA should not require you to open the Windows Run dialog and execute an unknown command.
What is ClickFix?
ClickFix is a social-engineering technique in which attackers attempt to persuade users to copy, paste and execute commands themselves. Microsoft has documented the technique across multiple campaigns.
What should I do if a CAPTCHA tells me to paste a command?
Do not paste or execute it. Close the webpage and avoid following the instructions.
Can antivirus software protect me from fake CAPTCHA scams?
Security software can help detect and block many threats, but safe browsing habits remain important. The best protection is to avoid executing suspicious commands in the first place.
Final Thoughts
Fake CAPTCHA scams show how scammers can turn a familiar “I’m Not a Robot” message into a social-engineering trap.
A CAPTCHA itself is not necessarily dangerous. The important thing is to pay attention to what the verification page asks you to do.
If a webpage suddenly tells you to open Windows Run, PowerShell or Terminal, copy an unknown command, install unfamiliar software, or disable security protection, stop and leave the page.
You should never need to execute an unknown computer command simply to prove that you are human.
For additional information, readers can consult these official resources:
- Google reCAPTCHA Help — Information about legitimate reCAPTCHA verification.
- Cloudflare Challenges Documentation — Information about Cloudflare’s legitimate security challenges.
- Microsoft Security: ClickFix Research — Microsoft’s research into ClickFix social engineering.
- Microsoft: FakeCaptcha Threat Information — Information about Trojan:HTML/FakeCaptcha.
- Microsoft: TerminalFix Campaign Analysis — Microsoft’s August 2026 analysis of a fake CAPTCHA campaign.
Disclaimer
This article is intended for general cybersecurity education and online-safety awareness. It does not provide instructions for creating, distributing, or using malicious software. Readers who believe their device or online accounts may have been compromised should use reputable security software and, where necessary, seek assistance from a qualified cybersecurity professional or the affected service provider.
Related Security Guides
- Back-to-School Scams 2026
- Back-to-School Scams 2026: Fake Scholarships, Grants & Laptops
- Back-to-School Shopping Scams
- Fake Student Grant Scams: Warning Signs to Watch For
- Fake Apple Support Scams: How to Spot and Avoid Them
- Fake Apple Support Scam
- Fake CAPTCHA / “I’m Not a Robot” Scams
