Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Scams & Phishing Security Education Videos Mobile Security Your Security Education Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
CAPTCHA Used as Bait For Growing Number Of Email Scams
Facebook   X   LinkedIn   Email

CAPTCHA Used as Bait For Growing Number Of Email Scams

June 22, 2024

Most of us are familiar with the funky CAPTCHA verification window that occasionally pops-up when signing onto a website. CAPTCHA systems lend a level of credibility to those of us asked to verify online that we’re human and not a bot. Seeing it makes us feel better about the site being more secure than others. After all, only a 100% legitimate website or service would dare use CAPTCHA, right? Wrong. This now Google-owned service has become a favorite bait for scammers who want you to believe they’re legitimate, and it’s working big-time. A Proofpoint study showed using CAPTCHA for cyberattacks has grown by 50% since last year.

If you haven’t already come across them, CAPTCHA are those odd boxes that pop-up when signing into some accounts. The highly popular verification system uses two different challenges, or formats, requiring a user response as a security and verification challenge. They can range from clicking on certain pictures, checking a box, or typing-in characters or words that appear in the CAPTCHA box.

CAPTCHA system isn’t the problem though, it’s the scammers who are using it as bait that’s the issue. The system was designed to keep bots and cybercriminals from using a website to steal information from users. Hackers don’t use CAPTCHA for its intended purpose, but rather hope to make a victim feel safe using the website. A user who feels safer is likely to give-up more sensitive information. Even automated security software looking for phishing sites can pass-up those using CAPTCHA.

Keep Fake CAPTCHAS Where They Belong

  • Since phishing and spam are hacker favorites for abusing CAPTCHA, the steps below can help keep hackers out of your accounts and put those bogus emails in the trash where they belong.
  • Unique passwords for all online accounts are truly necessary for safety. If a hacker gets a password you’ve used for other accounts, it gives them an open door to those accounts.
  • Use caution with links. Any sense that an email may not be legitimate is the reason not to click on links, or even open it in the first place. They can take you to fake websites and more, and they may use CAPTCHA to put you at ease.
  • Emails with bad grammar, poor spelling, and generic greetings are the hallmarks of phishing, so don’t take the bait.
  • Use two-factor authentication (2FA) when available. If a hacker gets your password to a site, they can’t logon to other accounts you have protected with 2FA. As long as you have your device in your possession, a hacker can’t enter, if it’s 2FA protected. It’s also a great time to change your passwords, using a combination of letters, number, and special characters to be as difficult to guess as possible.

How To Create A Strong And Unique  Password For Every Account

Education

How To Create A Strong And Unique Password For Every Account

Most of us know by now not to use the same passwords for different accounts; yet some of us still do. But users who continue to use passwords they know have been exposed in a hack are truly flirting with danger. In a recent study, Google found 1.5% of passwords are still being used despite those users knowing they’ve been compromised. A security researcher discovered more than 22 million unique passwords and over 770 million email addresses were made public on a popular hacker forum earlier this year. READ FULL STORY

Has Your Account Been Compromised? Five Cyber Smart Tips Everyone Can Use

Your Security

Has Your Account Been Compromised? Five Cyber Smart Tips Everyone Can Use

The transition to living life through our devices has become very real for scores of people and businesses. By now, the coronavirus has changed our lives in ways we never expected. This transition includes doing most things from home. Unfortunately, adapting to online life also gives bad actor’s a cornucopia of targets to exploit. There are proactive steps to take when you suspect an account may be compromised, including ways to help keep it from happening to begin with. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...