Fake CAPTCHA Scam: Don't Run Commands to Prove You're Human

Published August 25, 2026 · Safety & Privacy

CAPTCHAs are supposed to prove you're a person, not make you run computer commands. That difference matters because the Federal Trade Commission is warning about fake CAPTCHA pages that try to trick people into installing malware themselves.

The biggest warning sign

If a page that says “verify you're human” tells you to press keys such as Windows + R, paste something, and then press Enter, stop. According to the FTC, a real CAPTCHA will not ask you to run commands on your device.

Why the trick works

The screen can look familiar enough to feel routine. But the commands can paste and run hidden malware. Once malware is on the device, criminals may try to steal email logins, banking credentials, or other information stored or entered there.

If you already followed the instructions

The FTC recommends disconnecting the affected device from the internet, running an up-to-date security scan, and changing passwords from a different device. Turn on two-factor authentication where available. If you think personal information was exposed, use IdentityTheft.gov for a recovery plan based on what happened.

A simple rule to remember

A normal CAPTCHA may ask you to select pictures, type characters, or check a box. It should not ask you to open a Run window, Terminal, PowerShell, Command Prompt, or paste commands.

Already clicked or ran something suspicious? Follow this step-by-step guide →

Primary source: Federal Trade Commission Consumer Advice — “How to spot a CAPTCHA scam”, June 8, 2026.