How to report a website using a fake human check
A website that asks you to prove you are human may be using a legitimate CAPTCHA, but some pages imitate these checks to make visitors download malware, enable browser notifications, reveal personal information or follow a dangerous redirect. The warning signs can be subtle: an urgent instruction, a familiar-looking security logo, a copied page design or a prompt to press unusual keyboard shortcuts.
Knowing how to report a website that tricks you into a fake human check helps protect your accounts and other internet users. In Australia, the right reporting channel depends on what happened: a scam can go to Scamwatch, a cybercrime incident can be sent to ReportCyber, and a privacy issue may require attention from the Office of the Australian Information Commissioner.
Recognise a fake verification page
A genuine human verification tool usually has a limited purpose. It may ask you to select images, enter characters, tick a box or wait briefly while the browser is checked. It should not require you to install an unknown application, copy a command into PowerShell or Terminal, provide your banking password, upload identification or call a telephone number to “complete” the process.
Fake CAPTCHA pages often create pressure. Messages such as “your browser is infected”, “verification failed” or “click allow to continue” are designed to make the visitor act before thinking. A page may also display a countdown, flashing warning or fake browser notification. If the supposed verification asks for notification permission, close the tab rather than accepting it.
Unexpected redirects are another useful clue. A page claiming to verify access may send you through several unrelated domains, advertising networks or online betting pages. For example, a suspicious journey that ends at a gambling-themed page should be recorded as evidence rather than explored further. The destination may change, but the redirect chain can help investigators identify the wider campaign.
The web address deserves close attention. Look for misspellings, extra hyphens, unusual subdomains and a domain that does not match the organisation named on the page. A padlock only indicates that the connection is encrypted; it does not prove that the operator is honest or that the page is safe.
Stop the interaction and preserve evidence
Leave the page without completing the requested action. Do not download a “security tool”, run a command, scan a QR code or paste text into a browser console. If a file has already downloaded, do not open it. Disconnecting from the internet can be sensible when malware may be active, particularly if the device begins opening windows, displaying pop-ups or behaving unusually.
Take screenshots showing the verification message, address bar, visible branding and any warning or download prompt. Copy the full web address from the browser rather than relying on memory. Note the date and approximate time, how you reached the page, whether you clicked anything, and what happened afterwards. Australian time zones matter when several reports concern the same campaign, so record whether the incident occurred in AEST, AEDT, ACST or another local zone.
If you received the link by email, SMS or social media, keep the original message and its technical details where possible. Do not forward a suspicious message to friends or colleagues simply to warn them, because doing so can spread the link. Instead, use the platform’s built-in reporting feature and preserve the original sender, profile name and message timestamp.
Anyone who entered a password should change it immediately from a known-safe device or a trusted official app. Reused passwords need changing on every affected service. Turn on multifactor authentication, review recent account sessions and contact your bank promptly if payment details, one-time codes or identity documents were exposed.
Assemble a report that authorities can use
A useful report separates what you observed from what you believe. Write down the exact wording of the prompt, the page address, the redirects, the requested action and any information you supplied. Avoid describing the operator as criminal unless an authority has established that; precise observations are easier to assess than assumptions.
Include enough context to show how the page reached you. A link appearing in a Google result is different from one sent by an impersonated delivery company, a Facebook account or a text pretending to be Australia Post. If the page copied a business logo, mention the genuine business and the visual details that appeared to be imitated.
Details worth recording
- The full URL, redirect addresses and domain names
- Screenshots of the page, warning message and browser permissions
- The date, time, device, browser and Australian state or territory
- The original email, SMS, advertisement or social media message
- Any download, payment, login attempt or personal information disclosure
Where to send the information
- Scamwatch for suspected scams, misleading online approaches and fraud patterns
- ReportCyber for cybercrime, malicious software, compromised accounts or financial loss
- The platform, registrar or hosting provider when a page is being used to impersonate a service
- The OAIC when personal information appears to have been mishandled by an organisation
- Your bank, card provider or telecommunications company when an account or payment method is at risk
Scamwatch, operated by the Australian Competition and Consumer Commission, collects reports to identify trends and warn the public. It may not investigate every individual case, so a person who lost money or whose device was compromised should also use the more specific channels. If there is an immediate threat, serious identity concern or ongoing criminal conduct, contact police through the appropriate local pathway rather than relying only on an online form.
Choose the right Australian reporting pathway
ReportCyber is generally appropriate when the incident involves malware, unauthorised access, credential theft, ransomware or a significant online crime. The report can include the evidence pack and details of financial loss. If a fake check led to an account takeover, report the compromise even when the original page has disappeared.
Scamwatch is useful when the main issue is deception: a false security prompt, fake technical support, a bogus prize, a phishing message or a misleading website. It is particularly valuable for patterns affecting Australian consumers in different locations, from people working in Melbourne offices to households in regional Queensland or Western Australia.
Consumer protection may also be relevant. The Australian Consumer Law prohibits misleading or deceptive conduct, and the ACCC may use reports to identify conduct affecting the wider market. A business that collected information through a deceptive verification process should be contacted through an independently found address, not through the suspicious page itself.
Privacy concerns require careful handling. If an organisation collected names, contact details, identity documents or behavioural data, check its genuine privacy contact and consider the OAIC’s complaint process. A privacy complaint is stronger when it explains what was collected, why the collection appeared deceptive, what notice was provided and what harm resulted.
Reduce further exposure after reporting
Clear the permission granted by the fake page. In common browsers, review site settings and remove notification access for unfamiliar domains. Delete downloads and run a security scan using reputable, updated software. Browser history and cookies can be cleared after screenshots and notes are complete, although retaining some technical records may help an incident responder.
Check email, social media, banking and government-service accounts for unfamiliar logins or profile changes. Australian users should be especially cautious if they use the same password for online banking, MyGov-related services, shopping accounts and social platforms. Contact the financial institution through the number on the back of a card or its official app, not a number displayed by the verification page.
The Australian market is heavily exposed to fast-moving messages about parcel delivery, toll roads, tax refunds and account renewals. QR codes on posters, restaurant tables and parking signs can also lead to imitation pages, so a human-check screen reached through a QR code deserves the same scrutiny as one delivered by email. A page that asks for a browser command or payment before showing ordinary content is not made trustworthy by a familiar logo.
Keep a simple incident record containing the report reference numbers, dates, affected accounts and actions taken. If another person in the household uses the same device, tell them what occurred without sharing the dangerous link. For workplaces, notify the IT or security team through the normal internal channel and preserve the device if forensic review may be needed.
When a suspicious page is connected to an online campaign, supporting material can be difficult to interpret. A separate site or promotional page, such as the linked campaign, should be treated as evidence only when its relationship to the fake verification page is clear; do not assume that shared wording or a redirect proves common ownership.
Report the page even if it disappears before you submit the form. Include the last working address, cached screenshots, message headers and any replacement domains. Attackers frequently rotate domains while reusing the same scripts, logos and instructions, so an incomplete report can still help connect separate incidents.
The practical rule is simple: stop at the fake check, preserve the URL and screenshots, secure any exposed accounts, then send the evidence to Scamwatch, ReportCyber, the platform and your financial provider as appropriate.