Fake CAPTCHAs on the Shop Floor: The “Prove You’re Human” Trick That Can Cost You Time and Money

A close-up of a CAPTCHA-style "prove you're not a robot" prompt on a screen, illustrating the fake CAPTCHA scam that can catch busy workshop and trade teams out.
That everyday “I’m not a robot” box is being copied by scammers. A quick pause on the shop floor can save you time and money.

Quick Summary

  • A new scam uses fake CAPTCHA pages that ask you to “prove you’re human” by sending a pre-written text instead of ticking a box.
  • One tap can send multiple texts to premium-rate international numbers, quietly loading up your phone bill.
  • It works because the charges are delayed by weeks, so nobody links them back to the click.
  • You can hit these pages through hacked websites or dodgy online ads, not just spam emails.
  • Simple rule for the whole team: a real CAPTCHA never asks you to send a text,  if it does, close it.
  • For a busy workshop, the real cost is distraction, downtime and a nasty bill nobody saw coming.

The click nobody thinks twice about

Everyone knows the drill. A page pops up asking you to prove you’re not a robot, you tick the box or pick out the buses, and you’re on your way. When you’re halfway through a job, chasing a parts delivery or trying to get a quote out before lunch, it’s the last thing you’re going to scrutinise. And that’s exactly the problem. Scammers have worked out that the busier and more familiar something feels, the less likely anyone is to stop and question it. This new trick is built entirely around that reflex.

How the trick works, in plain English

Here’s the twist. Instead of ticking a box or clicking on pictures, a fake CAPTCHA page asks you to confirm you’re human by sending a text message. It’s a bit out of the ordinary, but the way it’s laid out makes it look like a normal step. You tap the button, your phone opens up a message that’s already been typed out for you, and all you have to do is hit send. Job done, or so it seems.

What you can’t see is what happens next. That one message can fire off several texts to premium-rate international numbers, sometimes dozens of them. Every one adds a charge, and because nothing shows up on screen when you press send, there’s no reason to think anything’s gone wrong. You close the page and get back to work, none the wiser.

Why the delay is the real sting

The clever, and frankly nasty, part is the timing. The charges don’t land straight away. They turn up weeks later on the phone bill, long after anyone remembers tapping a CAPTCHA. By then, who’s going to connect a line of unexpected charges to a verification box they clicked a fortnight ago? Almost nobody. That gap between the click and the cost is what makes this scam so effective and so easy to miss.

It’s the same pattern we see with a lot of workshop IT problems: the thing that bites you isn’t the loud, obvious fault, it’s the quiet one that builds up in the background until it lands all at once. Fake pages that look like the real thing are a growing headache, which is exactly why we wrote about a bogus Windows update doing the rounds. A fake update that can stop the whole job is well worth a read if you want to see how convincing these things have become.

It doesn’t always start with a dodgy email

You might assume this only catches people who click links in obvious spam. Not so. A lot of these fake CAPTCHA pages show up through legitimate websites that have been hacked, or through online advert networks that have been abused. You click something that looks perfectly normal, land on a page that feels familiar, and follow the steps without thinking twice.

Sometimes the browser is even nudged to make it harder to just back out or close the tab. This isn’t about being tech-savvy or not. It’s about habit. Your team sees CAPTCHAs every day, they trust them, and this scam turns that everyday trust straight back on them, usually when they’re busy and moving fast.

What it really costs a workshop

For a garage, a manufacturer or a trade business, the padded phone bill is annoying but it’s not the worst of it. The bigger cost is what a moment of misplaced trust says about how easily the team can be led down the garden path. If someone can be talked into interacting with a fake page mid-shift, a more targeted scam could just as easily be used to pinch a password or worm its way into your systems and that’s the kind of thing that genuinely stops jobs.

Downtime is money on the shop floor. Every minute someone spends untangling a scam, or every hour a machine sits idle because a system’s been compromised, is a minute or an hour you’re not billing. Keeping the workshop moving means keeping the daft, avoidable interruptions out. Some of those interruptions are technical, and some, like this one, come down to spotting a trick before it costs you. If you want a sense of how much small IT niggles quietly drag on productivity, our post Windows 11 is getting faster and less annoying looks at exactly that.

The one rule that stops it dead

Here’s the good news. For all the sneaky detail, there’s one dead-simple rule that beats this scam every time: a real CAPTCHA will never ask you to send a text message. That’s just not how it works. So the second a “prove you’re human” page asks you to send a text, tap a ready-made message or ring a number, that’s your cue to stop. Close the page. Don’t tap anything else, and don’t try to finish the step just to get rid of it.

It’s an easy rule to remember and an easy one to pass around the team over a brew. It takes a scam that’s hard to spot and makes it obvious, because now everyone’s got a clear line in the sand: text message equals close the page.

Keeping the whole team switched on

Telling your crew about this one is a good start, but the real win is building a habit of pausing when something feels a bit off, whether that’s a CAPTCHA, an email or a pop-up. The businesses that dodge this stuff aren’t the ones with the fanciest kit; they’re the ones where people trust their gut, slow down for a second, and feel fine about flagging something odd instead of quietly clicking on.

That’s more important than ever now, with automated tools and AI creeping into more corners of the working day. The same question applies: if something started doing the wrong thing, would anyone notice in time? Our article Don’t let AI agents run your workshop without a foreman digs into why a bit of human oversight matters just as much with clever new tools as it does with an old-fashioned scam.

A quick checklist for the team

  • Pass on the rule: no genuine CAPTCHA ever asks you to send a text.
  • Trust the gut: if a familiar step suddenly behaves oddly, stop and check.
  • No blame for flagging: make it easy for anyone to shout up about a dodgy page.
  • Eyeball the phone bills: keep an eye out for odd premium-rate or international charges.
  • Know the drill: agree what to do if someone realises they’ve clicked something they shouldn’t.
  • Keep it fresh: mention new scams as they crop up, don’t leave it to one training session a year.

The bottom line

This fake CAPTCHA scam is a tidy little example of how modern fraud actually works. It doesn’t smash through your defences, it borrows your habits, hides in the routine, and leans on a delay so that by the time the cost shows up, nobody remembers the click. For a busy workshop, the real lesson is about spotting the trick before it turns into wasted time and a bill you didn’t budget for. A few seconds of awareness can save a whole load of hassle and cost down the line. If you’d like a hand making sure your team knows exactly what to watch for and keeping the day-to-day IT running so the jobs keep flowing, let’s have a chat. Get in touch with EC Computers.

Scroll to Top