You’ve clicked “I’m not a robot” more times than you can count. Check a box, maybe pick out a few crosswalks or motorcycles, move on with your day. That habit is exactly what a new CAPTCHA scam is built on.

Instead of a checkbox, this fake CAPTCHA asks you to confirm you’re human by sending a text message. Tap the button, your phone opens a message that’s already written, hit send. It feels like the same routine you’ve done a thousand times.

It isn’t. And the bill shows up weeks later.

How the scam actually works

Security researchers at Infoblox detailed the scheme in an April 2026 report. The campaign has been running since at least June 2020. Researchers David Brunsdon and Darby Wise traced it to 35 phone numbers spread across 17 countries.

Here’s the mechanism. A compromised website or a malicious ad network redirects you to a fake CAPTCHA page, the kind of redirect that can happen from a perfectly ordinary site you had no reason to distrust. The page asks for the SMS “confirmation” and pre-loads a message with a phone number already attached. You hit send once, but the page is built to trigger several messages in sequence, sometimes to over a dozen numbers, sometimes to as many as 60. Some versions hijack your phone’s back button, so leaving isn’t as simple as it looks.

Each of those texts is a small charge to an international number the attackers lease. Individually, none of them look alarming. Together, a single visit can run up around $30 in charges. Because international SMS billing lags, that charge doesn’t show up until the next statement. By then, nobody remembers the CAPTCHA that supposedly proved they weren’t a robot.

Why this is a business problem, not just a phone bill

Thirty dollars per employee isn’t going to sink anyone. That’s not the risk worth paying attention to here.

The reason this scam works is the same reason phishing works. People move fast through things they’ve been trained to trust. Your team clicks through CAPTCHAs the way they sign for a package, without reading it, because they’ve done it a thousand times and nothing bad ever happened. That’s muscle memory, not carelessness, and it’s exactly what this campaign exploits.

The problem is that muscle memory doesn’t stay contained to CAPTCHAs. That same instinct is what gets an employee to click an unread attachment because an email looked routine, or approve a request because it seemed like business as usual. The dollar amount at stake with a fake CAPTCHA is small. The dollar amount at stake with the next thing that exploits the same instinct usually isn’t.

There’s a browsing hygiene angle too. These redirects often come through ad networks and compromised sites, which means an employee doing completely normal browsing on a work device can land here without doing anything wrong. If your business doesn’t have filtering or ad blocking on company devices, this is one more reason to get it.

What to tell your team

The fix doesn’t require a training budget or a new policy. It’s one sentence: a CAPTCHA will never ask you to send a text message. If one does, close the page. Don’t try to carefully back out of it, just close the tab.

That’s worth two minutes in your next team meeting, and it’s the kind of habit that only sticks with ongoing cybersecurity training rather than a once-a-year refresher. Not because this particular scam is going to bankrupt anyone, but because it’s a clean, low-stakes example of exactly the instinct you want your team questioning more often. Does this request actually match what the process normally looks like, or does it just look close enough that nobody bothered to check?

You’ve clicked through CAPTCHAs a thousand times without thinking, and for a thousand times that was fine. This is the one where it wasn’t. If you want help getting your team sharper on this kind of thing, or a broader look at where your business is exposed to social engineering like it, our security and defense team can help. Get in touch.