FTC warns residents about a new online trick disguised as a familiar security check
Roseville residents who spend time online are being warned about a growing scam that uses a familiar security feature to trick victims into installing malware. The Federal Trade Commission (FTC) says criminals are now creating fake CAPTCHA tests designed to steal passwords, financial information, and other sensitive data.
If you’ve spent any time online, chances are you’ve encountered those familiar tests designed to prove you’re human-checking a box labeled “I am not a robot” or selecting images that match a prompt, such as traffic lights or dogs. These security measures, known as CAPTCHA (Completely Automated Public Turing Test to tell Computers and Humans Apart), are widely used by websites to block spam, prevent malicious attacks, and protect online resources.
But scammers are now exploiting this familiar process to trick unsuspecting users.
The Federal Trade Commission (FTC) is warning the public about a growing “fake CAPTCHA” scam designed to install hidden malware and steal sensitive personal information from victims’ computers.
How the scam works
- The bait: You visit a website and are presented with what appears to be a standard CAPTCHA challenge.
- The “error”: After completing it, the page displays an error message claiming something went wrong.
- The trap: Instead of simply refreshing the page, you’re instructed to “fix” the issue by entering a sequence of keyboard shortcuts-such as pressing the Windows key + R, then Ctrl + V, and finally Enter.
The infection: Those keystrokes secretly open your computer’s Run command, paste a malicious script that was copied to your clipboard, and execute it. This can install information-stealing malware, giving criminals access to passwords, financial information, and other personal data.
Warning signs to watch for
- Keyboard commands: Legitimate CAPTCHAs will never ask you to use keyboard shortcuts, type commands, or download software.
- Unusual instructions: Real CAPTCHA tests only require simple actions like clicking a checkbox or selecting images.
- Unexpected downloads or pop-ups: Be cautious if a CAPTCHA triggers a file download, opens a command prompt, or launches another program.
What to do if you encounter one
- Do not follow the instructions. Close the browser tab immediately.
- Disconnect from the internet. If you already entered the commands, turn off Wi-Fi or unplug your router to limit the malware’s ability to communicate with criminals.
- Change your passwords. Use a separate, secure device to update passwords for your email, banking, and other online accounts.
- Run security software. Scan your computer with trusted antivirus or anti-malware software.
- Report the scam. File a report with the FTC through their ReportFraud portal.
As scammers continue to evolve their tactics, they often rely on familiarity and urgency to catch victims off guard. A simple CAPTCHA should never ask you to take extra steps beyond clicking or selecting images. If something feels unusual, trust your instincts and stop. Staying alert and recognizing these warning signs can help protect your personal information and keep your devices secure.
Roseville residents can reduce their risk by slowing down, questioning unusual instructions, and remembering that legitimate CAPTCHA tests never require users to run computer commands.

