You’ve probably seen a CAPTCHA dozens of times. CAPTCHA stands for “Completely Automated Public Turing test to tell Computers and Humans Apart.” It’s the familiar security check that asks you to prove you’re a real person by selecting pictures of traffic lights, checking a box, or entering characters displayed on the screen.
Cybercriminals are now creating fake CAPTCHAs that look legitimate but give very different instructions. Instead of simply asking you to identify pictures or click a box, the fake verification may tell you to press keyboard combinations such as Windows + R, paste something, run a command, open PowerShell or Terminal, or download a file. Following those instructions can actually install malware that steals passwords, banking credentials, and other information from your computer.
Remember this simple rule: A CAPTCHA should ask you to prove you’re human, not ask you to change or run something on your computer. If a “verification” screen asks you to copy and paste commands, open system tools, download software, or change security settings, stop. Close the page and do not follow the instructions.
We’ve become accustomed to clicking through verification screens without much thought. Attackers know that. Treat an unusual CAPTCHA like any other unexpected request: slow down, read what it is asking you to do, and question anything that doesn’t make sense.
Do you like these weekly tips? If you’ve missed some, are new to the university, or want to search for a tip on a certain topic, these are all stored in our Tip Archive.