Fake CAPTCHA Scams
Bruce Schneier examines fake CAPTCHA scams that abuse human-verification prompts as social engineering lures against users.
Bruce Schneier's blog post covers fake CAPTCHA scams, a social engineering technique in which attackers pose as CAPTCHA verification checks to manipulate users. The available page text is largely site navigation, and no specific campaign, victim, or malware family is named in the source.
- Fake CAPTCHA prompts are used as social engineering lures
- No specific campaign, victim, or malware named in the source text
Full article222 words · extracted from schneier.com · click to collapse
About Bruce Schneier

I am a public-interest technologist, working at the intersection of security, technology, and people. I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998. I'm a fellow and lecturer at Harvard's Kennedy School and the Munk School at the University of Toronto, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc. This personal website expresses the opinions of none of those organizations.
Related Entries
Featured Essays
- Four Ways AI Is Being Used to Strengthen Democracies Worldwide
- The CrowdStrike Outage and Market-Driven Brittleness
- How Online Privacy Is Like Fishing
- How AI Will Change Democracy
- Seeing Like a Data Structure
- LLMs’ Data-Control Path Insecurity
- AI and Trust
- The Value of Encryption
- The Eternal Value of Privacy
- Terrorists Don't Do Movie Plots
Blog Archives
Blog Tags
Latest Book
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2026/09/fake-captcha-scams.html