Scammers have found a way to use the familiar look of a CAPTCHA against you. This version does not ask you to click traffic lights or check a box. Instead, it tells you to press keyboard shortcuts, paste something, and hit Enter — and doing that can quietly run malware on your computer.
Fake CAPTCHA Scam Warning: Do Not Click This Prompt
Fake CAPTCHA Scam: The One Red Flag That Gives It Away
Most people treat a CAPTCHA as a routine part of going online. You click a box, maybe identify a few street signs, and move on. That automatic habit is exactly what this scam counts on.
A real CAPTCHA is designed to check whether you are a person, not a piece of software. But a fake CAPTCHA borrows that familiar look to trick you into doing something a real security check should never ask: running a command on your own computer.

What Makes a CAPTCHA Real vs. Fake
A real CAPTCHA might ask you to select images, type visible letters, click a checkbox, or wait while your browser runs a quick check. All of that stays inside the website. It does not need access to your device.
A fake CAPTCHA crosses a line. It may ask you to press Windows + R, then Control + V, then Enter. Those are keyboard shortcuts that open a system tool on Windows, paste whatever text is already on your clipboard, and run it. That is not a verification step. That is an instruction to execute a command.
The simple rule: a real CAPTCHA will not ask you to open the Windows Run box, PowerShell, Command Prompt, or Terminal. If a verification screen asks for any of that, close the page immediately.
How the Fake CAPTCHA Trap Works
You land on a webpage and see what looks like a routine security check. The screen may copy the style of a familiar verification page, or it may just say you need to complete a check before continuing. Instead of a normal puzzle, it gives you step-by-step keyboard instructions.

The hidden part is the clipboard. The webpage may have already placed a malicious command there before you noticed. So when you follow the instructions, you are not proving you are human. You may be launching the attack yourself.
Security researchers describe this as a manipulation tactic. The scammer is not breaking through a wall. They are convincing you to unlock the door for them.
What Malware Installed This Way Can Do
Malware installed through this method can steal login information stored on your device. That includes email passwords, banking credentials, saved browser passwords, session cookies, crypto wallet details, and screenshots of your screen.
Once a scammer has your email password, they can often reset passwords on every other account tied to that email. If they reach your bank or payment apps, the damage can show up as unauthorized transfers, purchases, or attempts to take over more accounts.
For anyone managing bills, retirement savings, or a fixed income, an account takeover is not just a tech problem. It can affect rent, groceries, medication costs, or access to money you depend on.
This Can Happen on Normal-Looking Websites
One reason this scam is hard to spot is that it does not always come from obviously suspicious sites. Security researchers have found fake CAPTCHA attacks appearing on compromised websites that otherwise look completely normal.
If attackers manage to inject malicious code into a legitimate website, visitors can see the fake verification screen even though the site itself belongs to a real business or organization. The warning sign is not always the website name. The warning sign is what the page is asking you to do.
Watch for Urgency Language
Fake verification screens often use pressure language to keep you from thinking carefully. They may say action is required, the browser needs to be fixed, access is blocked, or you must complete a step to continue.
That urgency is part of the trick. The goal is to keep you focused on getting past the screen, not on asking why a website would need access to your computer’s system tools.
Think of it like a fake security guard asking for the keys to your house instead of just checking your ID. A real CAPTCHA checks whether you are human. A fake one tries to take control of your machine.
What to Do If You Already Followed the Prompt
If you already followed the instructions on one of these screens, take it seriously but stay calm. The first step is to disconnect that device from the internet — turn off Wi-Fi or unplug the network cable. This can stop malware from communicating outward.

Next, run a full security scan using reputable software. If you are not comfortable doing that yourself, ask someone you trust or a computer repair professional for help.
Change your passwords — but do it from a different device you believe is clean. If you change passwords on the infected computer, the attacker may capture the new ones too. Start with your email account because email controls password resets for almost everything else. Then move to banking, credit cards, payment apps, and shopping accounts.
Turn on two-factor authentication where available, especially for email, banking, and payment accounts. Check your recent account activity and review bank and card transactions carefully over the next few weeks.
If financial accounts or personal information may have been exposed, report it. You can report scams to the Federal Trade Commission at ReportFraud.ftc.gov. If identity theft may be involved, use IdentityTheft.gov for a step-by-step recovery plan. Contact your bank or card issuer right away if you see anything suspicious — the sooner you report unauthorized activity, the better your chances of limiting the damage.
A Note for Website Owners
If you run a website — a small business, community organization, local news site, or WordPress blog — keeping it secure is not just about protecting your own data. A compromised site can expose your visitors to this kind of fake verification trap even if you had no intention of harming anyone.
Keeping plugins, themes, passwords, and admin accounts up to date is one of the clearest ways to protect the people who trust your site.
Frequently Asked Questions
What is a fake CAPTCHA scam?
A fake CAPTCHA scam uses a screen that looks like a real verification check but asks you to press keyboard shortcuts that open a system tool and run a hidden malicious command on your computer.
What is the one red flag that gives away a fake CAPTCHA?
If a verification screen asks you to press Windows + R, Control + V, and Enter — or tells you to open PowerShell, Command Prompt, or Terminal — it is fake. A real CAPTCHA never asks you to run commands on your device.
Can this happen on a normal website?
Yes. Attackers can inject a fake CAPTCHA into a legitimate website that has been compromised. The site may look completely normal, but the fake prompt can still appear to visitors.
What should I do if I already followed the fake CAPTCHA instructions?
Disconnect the device from the internet right away. Run a full security scan. Change your passwords from a different clean device, starting with your email account. Turn on two-factor authentication and check your account and bank activity for anything unusual.
What can malware from this scam steal?
It can steal email passwords, banking login credentials, saved browser passwords, session cookies, crypto wallet details, and other personal information stored on your device or accessible through your accounts.
Where do I report a fake CAPTCHA scam?
Report it to the Federal Trade Commission at ReportFraud.ftc.gov. If your personal information or identity may have been stolen, use IdentityTheft.gov for a recovery plan.
The Main Takeaway
A real CAPTCHA is a small checkpoint — a puzzle that stays inside the website. If a verification screen ever asks you to use keyboard shortcuts to open system tools, paste a command, or run anything locally on your device, close the page without following the instructions.
The strongest move is often the simplest one: slow down before you click, and ask whether the prompt is staying inside the browser or trying to control your computer.
Money Instructor provides educational information only and does not offer legal, cybersecurity, or financial advice. If your accounts or device may be compromised, contact your financial institution and a qualified technology professional promptly. Report suspected scams to ReportFraud.ftc.gov or the FBI’s Internet Crime Complaint Center at IC3.gov.