Fake CAPTCHA Attacks — How Do You Explain This Scam To Someone Who Isn’t Tech-savvy?

My dad was checking a bus schedule when a CAPTCHA told him to copy text, open a system box, and paste it. He stopped only because the wording looked odd, but now he thinks every CAPTCHA is dangerous. How do you explain fake CAPTCHA attacks clearly without burying a non-tech-savvy person in technical details?

A real CAPTCHA stays inside the web page. If it tells you to open Run, Terminal, PowerShell, Command Prompt, or paste anything into a system window, it’s a scam.

I’d explain it as a boundary: websites can ask you to click pictures, check a box, or type characters. They do not need you to operate the computer for them. The fake CAPTCHA is trying to make the victim run the attacker’s instructions while disguising them as a security check.

Since your dad stopped before pasting or running anything, he likely avoided the actual attack. He doesn’t need to fear every CAPTCHA. Give him one simple rule: “Clicking inside the CAPTCHA may be normal. Copying commands or leaving the browser is never part of proving you’re human.”

Realistically, he may stay suspicious for a while, and that is better than training him to trust CAPTCHA boxes automatically. Fake ones can look nearly identical to legitimate checks.

I’d describe it like a store asking to see your ID. The employee might ask you to show it, but they would never ask you to go outside, unlock your car, and follow instructions found in the glove compartment. In the same way, a normal website check happens on the page. Requests to press keyboard shortcuts, paste copied text, download a “verification” file, disable security software, or allow notifications have crossed into controlling the computer.

@0xbadger4 is right that stopping before running the command probably prevented the damage. I’d still have him close that tab, clear any downloads it triggered, and run the computer’s built-in security scan. Then make the rule slightly broader than “CAPTCHAs are safe”: treat any unexpected instruction that moves from a webpage into Windows or macOS as a stop-and-ask moment.

He may never feel comfortable with CAPTCHAs again, so give him a rule that does not require deciding whether one is genuine: a website can ask for a click, checkbox, picture choice, or text entry inside the browser. It does not need the Run box, Terminal, PowerShell, Command Prompt, or anything copied into the operating system.

I’d put even less emphasis on recognizing fake designs than @0xbadger4 does. The appearance can change, and scammers can copy familiar logos. The requested action is the giveaway. “Paste this command to prove you’re human” makes about as much sense as handing a stranger your house key to confirm your address.

Since he stopped before pasting or running anything, that is reassuring. More importantly, praise the hesitation rather than making him feel foolish. He noticed that the instructions broke the normal pattern, which is exactly the habit you want him to keep.

Compare a page asking him to select traffic lights with a page asking him to press Windows keys and paste a mystery instruction. The first is checking his answer. The second is recruiting him to install or launch something the browser cannot run by itself.

That is how I would explain the scam. The fake CAPTCHA is less like a broken security check and more like a burglar asking the homeowner to unlock the door. The copied text may look like nonsense because it is a command meant for Windows, macOS, or another system tool. Once pasted and confirmed, it can download malware, steal saved passwords, or change settings. The attacker needs the victim to perform that step because the web page normally lacks that level of access.

I would put a caveat on the “inside the page is normal” rule. A legitimate CAPTCHA can refresh, offer an audio option, or send you through another browser page. That alone is not proof of fraud. Judge it by what it asks you to do. A human check has no reason to request keyboard shortcuts, copied commands, software installation, browser extensions, notification permission, or changes to security settings.

Since he did not paste or execute the text, the command probably never did anything. Copying by itself is generally not the dangerous step. He can close the tab and copy an ordinary sentence to replace whatever remains on the clipboard. I would still check the downloads list and run the built-in security scan, especially if he clicked anything else or opened a downloaded file.

It is worth telling him that the bus company’s site may not have been the source. Bad advertisements, misleading search results, mistyped addresses, and redirects can land someone on these pages. That helps avoid the lesson becoming “all CAPTCHAs are malicious” or “the bus website infected my computer.” The useful lesson is simpler: when a web page suddenly starts giving instructions for operating the computer itself, stop there.

Don’t teach him to judge CAPTCHAs by logos, spelling, or how professional the box looks. That turns into a guessing game, and the fake may look more polished next time.

Give him a response routine instead: close the tab, reopen the browser, and reach the bus schedule through a bookmark or by typing the transit agency’s address himself. If the same strange demand appears again, stop and ask someone. This is easier to remember than a checklist of technical terms, especially since “Run,” “PowerShell,” and similar names may mean nothing to him.

I’d explain the copied text as an instruction for the computer, not an answer to the CAPTCHA. A normal human check wants information back from the person. The scam wants the person to carry hidden instructions from the website into a more trusted part of the machine. He does not need to understand the instruction. The fact that a random page supplied it is enough reason not to run it.

I’m a little less enthusiastic about automatically treating this as a security incident if he only copied something and then stopped. Text sitting on the clipboard does not normally execute itself. Replacing it by copying a harmless sentence is sensible, and checking the downloads list is quick. A scan is reasonable for reassurance, but I would avoid making him think that merely seeing the page means the computer is infected. That can reinforce his fear that every CAPTCHA is dangerous.

His suspicion was actually aimed in the right direction. The lesson is not “trust normal-looking CAPTCHAs.” It is “you are always allowed to abandon a verification and reach the service another way.” A real bus schedule will still be available after he closes a tab. Any page that pressures him to complete unusual computer instructions immediately has already failed the trust test.

The dangerous part isn’t the copying, it’s three keys in a row: the Windows key plus R, then Ctrl+V, then Enter. That specific combo opens the Run box, dumps whatever the page shoved onto your clipboard, and executes it. If your dad ever notices a website telling him to press those keys in that order, that’s the whole attack in one gesture. Nothing legitimate on the internet asks for it.

@darkwizard5 is mostly right that text sitting on the clipboard won’t run itself, but there’s a wrinkle worth knowing. A lot of these fake pages auto-copy the command the moment you click their ‘verify’ button, before you’ve agreed to anything. So the ‘copy this text’ step people picture isn’t always a visible step. The visible text can also differ from what actually lands on the clipboard. Point being, don’t build the lesson around ‘did he hit copy,’ build it around ‘did he paste it somewhere outside the browser and hit Enter.’ He didn’t, so he’s fine.

Where I’d gently push back on the thread as a whole: everyone’s handing your dad a rule, and rules are good, but under pressure people forget rules. What sticks better is a physical habit. Teach him that if a webpage ever tells him to touch the Windows key or type into a black or blue box, his hands leave the keyboard and he calls you. No judging whether the CAPTCHA looks real. No parsing what PowerShell means. Just a trained flinch.

One thing nobody flagged: these campaigns lean hard on urgency. Fake countdown timers, ‘verification expires in 30 seconds,’ flashing text. That pressure is deliberate because it stops people thinking. If your dad knows the rush is the tell, the odd wording won’t be his only defense next time, since the next one might be written perfectly.

And honestly, the fact that he stopped over a gut feeling is worth more than any checklist. Don’t let him talk himself into thinking he needs to become an expert. He doesn’t. He needs to keep doing exactly what he already did.

A real CAPTCHA checks an answer your dad provides, while the fake supplies the “answer” itself and tells him where to run it. Put simply: if the website already knows what to paste, it isn’t testing whether he’s human.