A cybersecurity threat that weaponises one of the internet's most familiar safety tools is surging in Australia, with the Australian Signals Directorate issuing a formal warning this week about fake CAPTCHA scams that are now being counted in the millions of attacks worldwide.

CAPTCHAs — the tick-boxes and image puzzles websites use to confirm a visitor is human — have long been a trusted part of online infrastructure. Now, however, criminals are turning them into a gateway for malware, tricking unsuspecting users into handing over access to their own devices.

How the Fake CAPTCHA Scam Works

Unlike a genuine CAPTCHA, which completes its check entirely within the browser, the fraudulent version directs users to take action outside the browser — typically by copying and pasting a script directly into their computer's terminal or command prompt. Once executed, that code can give hackers access to the device and, in some cases, sensitive browser session data.

What makes this method especially dangerous, according to Hammond Pearce, a senior lecturer at UNSW's School of Computer Science and managing director of the Digital Lies & Cyber Literacy Foundation, is that it effectively sidesteps the anti-malware protections most people rely on.

"You haven't got very many of the protections of the operating system working for you," Pearce said.

By persuading a user to manually run malicious code themselves, attackers bypass the security layers built into modern operating systems — layers that would ordinarily detect and block such threats automatically.

Why Fake CAPTCHAs Are Becoming So Common

CAPTCHAs were once mainly encountered when creating a new online account. Today, they appear far more frequently — often on a user's very first connection to a website. Pearce attributes this sharp increase to "the explosion of AI agents online", as website operators attempt to screen out artificial intelligence bots crawling their pages.

That increased prevalence has created the perfect cover for criminals. When users are completing CAPTCHAs constantly, a malicious one is far easier to slip past their guard.

Pearce noted that while fake CAPTCHAs are more likely to appear on less reputable websites, hackers are also capable of intercepting connections to legitimate sites — meaning no browsing session is entirely beyond risk.

The scale of the problem is significant. Pearce said the number of fake CAPTCHA attacks are "now measured in the millions", reflecting how rapidly this form of cybercrime has grown.

Why Modern Browsers Are Your Best Defence

There is some reassuring context. Pearce noted that major browsers — including Chrome, Firefox and Edge — have invested heavily in their own security architecture, making them, in his words, "about the safest piece of technology there is on your computer."

It is also now significantly harder for criminals to exploit a person's internet connection directly than it once was. The danger with fake CAPTCHA scams, however, is that they are specifically designed to lure users away from that browser safety net — which is precisely why Pearce urges people never to follow instructions that take them outside the browser window.

How to Spot a Fake CAPTCHA and Protect Yourself

Pearce's advice centres on one core principle: a legitimate CAPTCHA will never ask you to type anything manually or leave the browser to complete it.

  • Be suspicious immediately if a CAPTCHA prompts you to type a random string of characters on your keyboard.
  • Never paste code into a computer terminal, command prompt, or run dialog as part of a website verification step.
  • Stay within the browser. "Be very wary of anything that might take you out of the safety of the web browser," Pearce said.
  • Ask yourself why. If something feels unusual, Pearce recommends pausing and asking: "Why? Why do I need to do this?" If there is no clear, logical answer, treat it as a red flag.

The Australian Signals Directorate's warning underscores that this is not a niche threat. As CAPTCHAs become an ever-more routine part of daily internet use, so too does the opportunity for criminals to exploit our familiarity with them. Staying alert to what a real verification check looks and feels like remains the most practical line of defence available to everyday Australians.