Fake CAPTCHA Scams Are Now Hitting Phone Bills
How "I'm Not a Robot" Checks Are Being Turned Into SMS Fraud
A new scam campaign is abusing fake CAPTCHA pages to quietly charge victims through international text messaging fees. What looks like a harmless “prove you’re human” prompt can trigger dozens of premium SMS messages in the background, leading to unexpected charges on mobile bills. Researchers say some victims have reported costs reaching roughly $30 from a single interaction.
This tactic represents a shift in how CAPTCHA scams work. In the past, fake CAPTCHA pages were mostly associated with malware downloads or clipboard hijacking attacks. Now cybercriminals are using them for telecommunications fraud known as International Revenue Share Fraud, often shortened to IRSF.
Why It’s Important
Most people understand that suspicious downloads are dangerous. Far fewer realize that sending a text message can also be weaponized.
The reason this scam works so well is psychological familiarity. CAPTCHA systems are everywhere online. Users are trained to click through them quickly without much thought. Attackers take advantage of that trust by replacing standard browser verification with prompts that ask users to send an SMS message instead.
Researchers from Infoblox discovered that these campaigns can chain together multiple SMS prompts, sometimes causing victims to send up to 60 messages to premium rate international numbers spread across numerous countries.
This type of fraud often flies under the radar because the financial impact is delayed. Victims may not notice the charges until their next billing cycle, long after they visited the malicious page.
The scam also harms telecom providers. Revenue sharing agreements tied to premium messaging services can unintentionally funnel money back to the scammers operating the scheme. Providers may then absorb losses through disputes and refunds.
What It Is / How It Works
At the center of this campaign is a social engineering technique designed to feel normal.
Here is the basic flow:
A user lands on a malicious or compromised website.
The site displays a realistic CAPTCHA prompt.
Instead of verifying inside the browser, the page asks the user to “confirm” they are human by sending a text message.
Tapping the button automatically opens the phone’s SMS application with a prefilled message and destination number.
Additional fake verification steps trigger more messages to more international numbers.
Researchers linked these attacks to “Click2SMS” operations that abuse built-in smartphone messaging features. Some campaigns also use traffic distribution systems, or TDS platforms, to redirect users through layers of malicious advertising infrastructure before delivering the fake CAPTCHA page.
One important detail is that the victim technically authorizes the messages themselves. That makes the activity harder for carriers and fraud systems to block automatically.
The broader tactic resembles earlier scam ecosystems studied by academic researchers. Previous studies on popup scams and technical support fraud showed that attackers consistently rely on urgency, fake warnings, and familiar interface elements to manipulate users into self compromise.
In many ways, fake CAPTCHA scams are the modern version of those earlier schemes. Instead of fake virus alerts, attackers now exploit trust in verification systems.
How to Mitigate
The good news is that this scam is avoidable once you know what to look for.
A legitimate CAPTCHA never requires you to send a text message. Verification happens directly inside the webpage or app itself. If a site asks you to open your messaging application to prove you are human, leave immediately.
Other ways to reduce risk include:
• Review your mobile bill regularly, especially international SMS charges.
• Ask your carrier to disable premium rate or international texting if you do not use those features.
• Avoid clicking CAPTCHA prompts on suspicious streaming, download, or adult content websites, where malicious advertising networks are common.
• Keep mobile browsers and operating systems updated to reduce exposure to malicious redirects.
• Use reputable mobile security software that can detect phishing pages and known scam domains.
How to Configure/Use
One practical security improvement is enabling carrier restrictions on premium messaging.
Most major telecom providers allow users to:
• Block premium SMS services.
• Restrict international texting.
• Enable billing alerts for unusual activity.
• Require account authorization before adding premium features.
These settings are usually available inside your provider’s account portal or customer support application.
A helpful security tool for this type of threat is Malwarebytes. Its browser and phishing protections can help identify malicious redirects and scam pages before interaction occurs.
Want to support my work? Consider buying me a coffee ☕
Feature Highlight
Closing Encouragement
Cybercriminals continue to evolve old tricks into new formats, but most scams still depend on one thing: getting people to react before thinking critically.
The safest approach is slowing down when a website asks for unusual behavior. CAPTCHA systems are meant to reduce automation, not trigger messaging apps, downloads, or system commands. If something feels out of place, trust that instinct.
Awareness remains one of the strongest security tools available. The more familiar people become with scams like this, the harder these campaigns become to scale.
What’s the strangest or most convincing fake verification prompt you’ve encountered online recently?
Sources
Malwarebytes, “Fake CAPTCHA scam turns a quick click into a costly phone bill”
Infoblox Threat Intelligence, “Hold the Phone: International Revenue Share Fraud Driven by Fake CAPTCHAs”
Forbes, “This SMS Pumping Attack Starts Hitting Your Phone Bill After 1 Click”
The Hacker News, “Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud”
Cybernews, “Google users receive $30 bills after fake CAPTCHA scammed them into sending premium text messages”
TechRadar, “Fake CAPTCHAs are driving a global SMS scam campaign”
HackRead, “Fake CAPTCHA Scam Abuses Verification Clicks to Send Costly International Texts”
Malwarebytes, “Fake CAPTCHA scams: how ‘I’m not a robot’ installs malware”
Research paper: “Dial One for Scam: A Large Scale Analysis of Technical Support Scams”
Research paper: “Large Scale Analysis of Pop-Up Scam on Typosquatting URLs”




