Blog
Topic
All
AIoT
Products and technologies
Industries
All
Logistics
Building
Sustainability
Business trends
Cybersecurity
Events
Trends
Industry News
Company News
Product Announcement
Search blog
Blog
Filter
Cancel
All
AIoT
Products and technologies
Industries
All
Logistics
Building
Sustainability
Business trends
Cybersecurity
Events
Trends
Industry News
Company News
Product Announcement
Reset
Submit

Phishing Threat Uses CAPTCHAs to Hack Accounts

 

Three Tips from Hikvision to Avoid Becoming a Victim of CAPTCHA Phishing Hacks

 

Cybercriminals are using CAPTCHA phishing to hack accounts, according to the SC Magazine article, “Phishing pages leverage CAPTCHAs to fool users, evade detection.”

CAPTCHAs, also known as reCAPTCHAS, are typically used on legitimate websites as a way to verify that a visitor is a human, not a robot.

“Users have undoubtedly become familiar with CAPTCHAs through the regular use of the web, so a CAPTCHA can preserve the illusion of normality when users click links offered to them in phishing emails,” said principal researcher for KnowBe4, Eric Howes, in the SC Magazine article.

The story offered a few suggestions to identify fraudulent or phishing CAPTCHAs to prevent becoming a victim. These included identifying:

  • CAPTCHAs on a blank website background, which are often suspicious.
  • CAPTCHAs on a website that doesn’t typically use them (i.e. Microsoft login pages).

Hikvision on CAPTCHA Phishing Examples
Hikvision’s senior director of cybersecurity, Chuck Davis, covered this hacking method in a recent blog, “Examples of reCAPTCHAS Hacks and Phishing Threats, Plus 4 Tips to Avoid Becoming a Victim to these Cyberattacks.” It becomes a “bait and switch” where a valid method from legitimate sites is used to trick visitors into disclosing information.

“What this means is that if you are tricked into clicking on a link or opening an attachment from a phishing email, you might be met with a real, reCAPTCHA challenge which has you check a box to prove that you are not a robot. In this context, a ‘robot’ or a ‘bot’ is an automated program that scours the Internet looking to scrape data from sites, create fake accounts or post fake reviews. When you click that box and pass the reCAPTCHA test, you are sent to the malicious phishing page. While clicking that box is an easy test for humans, the automated cybersecurity tools that check the links in our email work much like the malicious bots and are unable to get past that reCAPTCHA to determine if the page has suspicious or malicious content,” said Davis, in the Hikvision article.

Three Tips to Avoid Being a Victim of this CAPTCHA Scam

  1. Follow standard phishing detection recommendations.
     
  2. Don’t leave your guard down when you see something that looks credible, like a reCAPTCHA.
     
  3. Use a password manager and have it automatically fill in your username and password. If you’re on a phishing site, it won’t paste your credentials into an unrecognized domain, for example microsoft.com versus miicrosoft.com.
Cybersecurity

Subscribe to newsletter

Subscribe to our email newsletter to get the latest, trending content from Hikvision

Hikvision.com uses strictly necessary cookies and related technologies to enable the website to function. With your consent, we would also like to use cookies to observe and analyse traffic levels and other metrics / show you targeted advertising / show you advertising on the basis of your location / tailor our website's content. For more information on cookie practices please refer to our cookie policy.

 

Contact Us
Hik-Partner Pro close
Hik-Partner Pro
Security Business Assistant. At Your Fingertips. Learn more
Hik-Partner Pro
Scan and download the app
Hik-Partner Pro
Hik-Partner Pro
back to top

Get a better browsing experience

You are using a web browser we don’t support. Please try one of the following options to have a better experience of our web content.