Skip to main content
IT Service Status
IT Service Status

Beware of Fake "Verify You're Human" Prompts

You know the process: click a box, select some images, and prove you are not a robot. It has become such a familiar step online that scammers have now started to exploit it by tricking people into infecting their own devices.

In fact, the Federal Trade Commission (FTC) has issued a consumer alert about this exact scam, called “Fake Captcha.” Here's what it looks like and how to protect yourself.

How The Scam Works

You are browsing a website—maybe one you reached through a search result, an ad, or a link in an email—and an unexpected verification box pops up. It looks like a normal CAPTCHA, asking you to confirm that you are human. But instead of clicking images or typing distorted text, you are told to do something like:

  • Press Windows + R (or Cmd + Space on a Mac)
  • Press Ctrl + V (or Cmd + V) to paste something
  • Press Enter

Following these steps doesn't verify anything. It is actually pasting and running a hidden command that installs malware on your device. From there, attackers can steal saved passwords, email credentials, or NetID logins, or gain remote access to your computer.

What to Look for in This Scam

A real CAPTCHA never asks you to open a Run box, Terminal, or PowerShell, or paste anything. It stays entirely inside your browser—click on a checkbox, select some images, or type a short code. If a "verification" step asks you to leave the browser, use a keyboard shortcut, or paste something into another window, stop. It is not a CAPTCHA, no matter how official it looks.

If You Already Engaged with a Fraudulent CAPTCHA

If a verification prompt had you press a key combination or paste something, and something seemed to download or run afterward:

  1. Disconnect the device from whatever Wi-Fi you are on.
  2. Don't log into anything else on that device in the meantime. Contact security@northwestern.edu right away—the sooner we know, the faster we can help contain it on University-owned computers.
  3. Once it is safe, or from a different device, change your NetID and/or personal account passwords and check that Multi-factor Authentication is still enabled on your accounts.

Report It

If you spot one of these fake prompts on a site, let us know at security@northwestern.edu. You can also report it to the FTC at ReportFraud.ftc.gov. To learn more about protecting your information and recognizing phishing attempts, visit the Information Security Office's Secure Northwestern site.

Source: Federal Trade Commission, "How to spot a CAPTCHA scam," June 2026