TL;DR: A scam is spreading that copies the "prove you're not a robot" CAPTCHA everyone clicks through without thinking, except this version asks you to send a text message instead of ticking a box. That single tap can trigger charges to premium rate or international numbers, and because the bill doesn't land for weeks, almost nobody connects it back to the page they were on.
Genuine CAPTCHAs never ask for a text. If one does, close it.
You've done a CAPTCHA a hundred times without really registering it. Tick a box, pick out the traffic lights, get on with your day. That habit is exactly why this scam works.
Instead of the usual click-and-move-on process, the page asks you to confirm you're human by sending a text. Your phone opens a message that's already written, and all you have to do is hit send. It looks like one more small step in a process you've done a thousand times before.
What's actually happening behind that button is different
That single send can fire off multiple messages to premium rate or international numbers, sometimes dozens in one go. Each one adds a small charge, and because none of it shows up on your bill straight away, there's nothing at the time to make you suspicious. By the time the charges appear, the "verification" you completed is long forgotten and the two never get connected.
Not sure where to start?
Let's talk it through.
Have a quick, no-obligation call with our team.
No pitch, just answers.
Where these pages come from
Fake CAPTCHA pages rarely show up because someone typed a dodgy address into their browser. Most people land on one after being redirected, either through a compromised website that's otherwise perfectly legitimate, or through a malicious ad network serving up something it shouldn't. You click a link that looks fine, arrive somewhere that feels familiar, and follow the instructions without questioning it. Some versions of the scam even restrict what the browser lets you do next, making it harder to just back out and leave.
None of this depends on anyone being careless with technology. It depends on habit. Your team trusts CAPTCHAs because they see them constantly, and when something looks routine, people move fast rather than pause and check.
What to do if someone on your team has already sent the text
If it's already happened, speed matters more than anything else. Contact the mobile provider straight away and ask them to block premium rate and international SMS services on that number. Then go through recent charges on the account so you know what you're actually dealing with. Catching it quickly limits the damage and stops the same thing happening again on the next bill cycle.
The one rule worth repeating to your team
A CAPTCHA should never ask you to send a text message. Not once, not as a backup option, not as part of a "quicker verification." If you see that request, close the page and don't interact with it any further.
A few habits make this easier to catch across a whole team:
Bookmark the login pages and services you use regularly instead of clicking through from search results or ads. Review mobile bills monthly rather than skimming them, since these charges are built to hide in the small print. Where it's possible, ask your provider about blocking premium SMS services at the network level so the option isn't there to trigger in the first place.
This kind of scam is only going to become more common. It doesn't rely on getting past security software, it relies on getting past people, and that means the fix has to include people too. A five minute conversation with your team now is a lot cheaper than untangling a phone bill full of charges nobody can explain in six weeks' time.
Is it ever normal for a CAPTCHA to ask for a phone number or text message?
Is it ever normal for a CAPTCHA to ask for a phone number or text message?
No, not in any legitimate implementation. Standard CAPTCHA systems work through checkboxes, image grids, or a short puzzle, and none of them need your phone number or a text message to confirm you're not a bot. If a page asks for either, treat it as a red flag straight away rather than something to work through.
How much can this actually cost a business?
How much can this actually cost a business?
It depends on how many messages get sent and to what kind of number, but the costs stack up faster than people expect because it's rarely a single text. Premium rate and international numbers charge per message, and if the scam fires off a batch in one go, that's a batch of charges landing on one bill. On a shared or pooled business phone plan, one person's mistake can affect the whole account.
Does this only affect personal mobiles, or could it hit work devices too?
Does this only affect personal mobiles, or could it hit work devices too?
Any device capable of sending an SMS is a target, which includes company phones, tablets, and desktops set up to send texts through a linked messaging app. Work devices can actually be more exposed than personal ones, since business phone bills often get less scrutiny month to month than someone checking their own account.
Our team already knows not to click suspicious links. Is that enough to avoid this?
Our team already knows not to click suspicious links. Is that enough to avoid this?
Not on its own, because this scam doesn't rely on an obviously suspicious link. People often land on the fake page through a redirect from a site or ad they'd normally trust, so the usual "don't click dodgy links" training doesn't cover it. The rule that actually stops this one is narrower and easier to remember: a CAPTCHA never needs a text message, full stop.
Is this a one-off scam or something we should expect to keep seeing?
Is this a one-off scam or something we should expect to keep seeing?
Expect to keep seeing it, and expect variations on it. Scams built around habit and routine tend to stick around longer than ones relying on a technical flaw, because there's nothing for security software to patch. The page changes, the wording changes, but the underlying trick of dressing up an unusual request as a normal one isn't going anywhere.
If you'd like help building this kind of awareness into your team's day to day, or want a second set of eyes on what else might be slipping through, get in touch.