The Click Trick: How Fake CAPTCHA Scams Fool Us All

Posted on: Last Updated: Views: 21
R. Paul Wilson

Author:

Expertise: Casino Scams, Cheating, Vegas

Scams seem to come in waves, and we are currently experiencing a tsunami from multiple directions as new versions of old software update our devices and our lives, introducing fresh gaps in previously sealed fences. While the persistent advice to remain vigilant and follow a few simple rules will protect us most of the time, occasionally a new twist on an old scam can catch out even the most vigilant online explorers.

This will undoubtedly resonate with you as a scam, but since it has managed to trick even the most cynical of potential suckers, allow me to set the scene with a bit of context because when it comes to getting caught out, context really is king.

The Scams We Couldn’t Put on TV

While filming for the BBC’s Real Hustle TV show, there was a large board in our production office that displayed every kind of scam I had ever read or heard of. As the season progressed, ideas would be taken from that board and developed into television pieces. Some of the most obvious candidates were quickly adopted in the first couple of seasons, but a few remained on that board, waiting for the day they might be brought to life.

Some concepts never made it to the show, such as “pickpocketing monkeys”, which I would have loved to try, but apparently, adopting a baby primate and training it for several years seemed impractical. Great con games like The Razzle took years to convince producers they would work because they seemed dry on paper, but once filmed, their power was obvious, often becoming the highlight of that episode.

Two types of scams were categorically off-limits for both producers and myself, as they presented problems that could not be overcome once the nature of the show was revealed to on-screen victims.

The first type involved romance-based scams, where love (and sex) is used as bait for lonely individuals who sacrifice common sense for hopeless promises. These scams remain prevalent, but we could do little to expose them in our style because once you engage someone emotionally, returning their money does not erase any sense of loss once the scam is revealed.

For a TV show, manipulating anyone in this manner was simply not feasible.

The second type was imposter scams, where we would pretend to be someone rich or famous to gain trust and secure money or property. While I had multiple proposals for variations on this scam, the simple fact was that the BBC would not allow us to impersonate a real person for fear of legal repercussions.

Fair enough, you wouldn’t like it if someone pretended to be you on national television, and I felt the same way when Russian television cast their version of me as a portly buffoon constantly producing a stream of playing cards from his mouth!

Another reason was that producers doubted we could pull it off; pretending to be an actual person seemed more difficult than inventing a new character for the sake of a con game. Yet, some clown once spent years convincing people he was Status Quo guitarist Rick Parfitt, despite looking nothing like him in photographs; all he had was shoulder-length blonde hair and confidence!

The Night We Accidentally Became Impostors

Despite these self-imposed rules, we still managed to impersonate a famous celebrity, purely by accident! After pulling a scam in a luxury hotel suite, we needed to escape from the hotel in disguise, choosing costumes where Jess wore a brightly colored wig and dark glasses, flanked by me as a suited bodyguard. This was mainly to make the getaway scene more entertaining, as a couple of boiler suits and a large laundry basket would have been just as effective.

Amazingly, the suite from which we executed our con, and subsequently needed to escape through a busy lobby, was in a high-end Kensington hotel where a very famous female singer happened to be staying, and when we exited, we found ourselves followed by a large crowd of paparazzi! The wig and (confused) bodyguard were enough to convince the photographers that Jess must be the pop star they were waiting to capture, and by the time they realized their mistake, she (the real star) had been driven away, leaving two dozen photographers furious at us for distracting them!

I don’t think Jess really looked like Lady Gaga (or whoever), but the timing of our exit and the costumes we wore convinced the waiting press pack without question that we must be who they were expecting. This illustrates where these types of scams work best: in locations and situations where they make complete sense.

Want to pretend you’re Brad Pitt? If you have the hair, the jawline, and the sunglasses to pull that off, congratulations! However, it would be much easier to convince someone at the Sundance Film Festival than at a pub in Glasgow on a Friday night. Just ask Bruce Willis, who was once refused entry into a Glasgow casino because no one believed he could possibly be in town (he was shooting a film nearby).

Why Familiar Online Checks Make Scams Convincing

However, if place and time collaborate to support your story, doors and bank accounts can open almost by magic. This highlights why the latest online scam is proving so effective.

The pervasive nature of certain dangerous procedures has exposed millions of people to being ripped off. For example, QR codes are particularly worrying; I once experimented by replacing the codes on several restaurant tables with a link to my own temporary website that said, “This could be a SCAM; ask for a real menu!” in several languages. Similarly, the persistent need to accept cookies has protected exactly no one from their misuse since we all habitually click accept to get rid of their annoying interruption on every website we visit (this is the product of ineffectual politicians creating useless procedures for easy political gains).

However, there is one regular procedure we all recognize as a way to identify us, not as individuals, but as human beings rather than ‘robots’ or rogue software.

CAPTCHAs, those irritating tests asking you to click on traffic lights or type distorted text, were originally designed to differentiate between humans and bots. Once a useful security measure, they have become so commonplace that we rarely question them.

This familiarity is precisely what scammers exploit.

How Fake CAPTCHA Scams Work and How to Stop Them

The trick described here is one variant of a fast-moving threat. Microsoft’s security team has also tracked a related technique called ClickFix, where the fake verification screen skips notifications altogether and talks the visitor into pasting a command straight into a system tool like PowerShell or Terminal, serious enough that the FTC issued its own consumer alert on it in June 2026. The version most people still run into today, though, usually starts with something simpler.

Fake CAPTCHA scams deceive users by mimicking the appearance and behavior of legitimate CAPTCHAs. You might encounter a dubious website or a pop-up that says something like, “Click Allow to verify you’re not a robot”. It feels routine, so many people do not think twice. However, instead of verifying anything, that click grants the website permission to send push notifications, often incessant alerts designed to resemble system warnings.

Once you’ve granted permission, you may begin to receive alarming (fake) messages such as “Your computer is infected!” or “Click here to clean your system”. These can lead you to dangerous sites: malware downloads, phishing pages, or fraudulent tech support schemes. Suddenly, you’re not just dealing with annoying pop-ups; you have become a target for more serious attacks.

These scams are effective because they hijack something we instinctively trust. CAPTCHAs appear official, and scammers exploit that visual familiarity. They also take advantage of browser features that most users are unaware of, such as automatic notification permissions. To avoid falling for this trap, be cautious of CAPTCHAs that seem out of context, especially if they ask you to press “Allow” for anything unrelated to solving a puzzle.

You can protect yourself by disabling push notification requests in your browser settings, using a reliable ad blocker, and keeping your software updated, but if you have already clicked on one, do not panic. Revoke site permissions, run a malware scan, and consider resetting your browser. Awareness is your best defense, and understanding how these scams operate can help you identify them before they cause real harm.

When looking into how commonplace this method has become, I began to question my own online activity. How many CAPTCHAs have I completed without thinking? Did any pop up a window or ask me to allow something? The answer (thankfully) was “no”, but I still ran a check on my system because you never know what else might have tricked me into clicking.