Ah, the good ol’ CAPTCHA. You’ve seen them a million times: the original form is/was a small image with some distorted numbers and letters you have to decipher and type into a text box.
Newer approaches include the photo CAPTCHA, where you’re clicking all the photos with stop signs or motorcycles or bridges in them, or the reCAPTCHA, Google’s take on the mechanism where you simply click a box that says “I’m not a robot.”
Unfortunately, the FTC and many cybersecurity firms are warning that scammers have now figured out ways to turn the CAPTCHAs we know and love into yet another way to scam us.
Here’s what you need to know about this new scam.
What Are CAPTCHAs and RECAPTCHAs?
CAPTCHA is an acronym for “Completely Automated Public Turing test to tell Computers and Humans Apart.” And that’s exactly what they attempt to do: provide an obstacle that humans can easily solve but computers cannot.
Text and photo-based CAPTCHAs and reCAPTCHAs are three ways to do the same thing: prove you’re a real, living and breathing human being trying to use whatever website the CAPTCHA is on.
In other words: It’s an old-ish-school way of weeding out bots, preventing automated denial of service attacks, and so on.
Legitimate CAPTCHAs Are Not Scams
First, it’s important to clarify that real CAPTCHAs are not scams. Scammers haven’t found a way to compromise the technology itself, which cannot transmit anything more than your answer (typing the random characters, clicking the photos, and so on).
So you don’t need to treat every CAPTCHA as a threat.
What you need to watch out for is when CAPTCHAs mix familiar, legitimate steps with something unfamiliar or unusual.
How the CAPTCHA Scam Works
There are lots of variations on this theme, but here’s how the basic CAPTCHA scam works.
Step 1 will always be something very familiar-looking: type the characters, click the pictures, click the box to prove you’re not a robot.
It’s Step 2 where they get you.
A scam site will insist that something was wrong, and they need another layer of verification. This is the unfamiliar part and the part that could compromise your systems or accounts. It might look like:
- Providing your email address so you can “click a link”
- Downloading a file to “verify”
- Telling you to open the Windows Run dialog (Win + R), then pasting a code (which is malicious code that will compromise your system
- If on mobile, texting a code to a number
Of course, with all of these, you’re not verifying anything. You’re giving up your credentials, downloading malware, or even executing code directly.
Remember:
- Step 1 looks just like it should, or close to it.
- Step 2 looks different, unfamiliar, and maybe a little iffy. It might also look urgent or scary to trick you into not thinking too hard about it.
Tips for Staying Safe
CAPTCHA scams are tricky, but they aren’t impossible to spot. Use these tips to reduce risk at your organization.
1. Spot the unfamiliar
Real CAPTCHAs never ask for contact info, prompt you to send a text message, or ask you to run a command.
If you see any of those behaviors, it is 100% going to be a scam. Close out immediately.
2. Put it in manual
If you sense something is off, close out and then open a new tab or window and manually navigate to where you thought you were. Chances are, if you manually type in the website name, that scammy CAPTCHA won’t be there.
3. Keep it clean
Many of these kinds of attacks happen through compromised sites or advertising networks. It’s always possible that a mainstream site gets compromised briefly, but the odds of you running into that are low.
Instead, most of the time these things are happening on obscure or sketchy sites your team probably doesn’t have a business need to be on.
So: keep it clean, stick to mainstream sites, and your risk profile goes way down.
4. Tighten your IT security
Many of these scams can be blocked at the network/DNS level. Work with your IT provider to make sure your IT security applications and protocols are up to date.
This is the kind of thing we help client businesses with all the time. If we can assist you, give Blue Ridge Technology a call.