Every firm we work with has had the phishing talk. Don’t click links from strangers, check the sender, hover before you trust it. Good habits, all of them. None of them help here.
A new scam skips email entirely and goes after a click your staff has made a thousand times without thinking about it: the CAPTCHA. “Click here to prove you’re not a robot.” Except this one doesn’t want a checkbox. It wants a text message.
Tap the button, the phone opens a message that’s already written, hit send. It feels like the same routine everyone’s done a thousand times. Would your staff catch it, or would they just hit send? That’s the question this scam raises for a firm, and it has nothing to do with the phone bill.
How the scam actually works
Security researchers at Infoblox detailed the scheme in an April 2026 report. The campaign has been running since at least June 2020. Researchers David Brunsdon and Darby Wise traced it to 35 phone numbers spread across 17 countries.
Here’s the mechanism. A compromised website or a malicious ad network redirects the browser to a fake CAPTCHA page, the kind of redirect that can happen from a perfectly ordinary site a paralegal had no reason to distrust. The page pre-loads a text message with a phone number already attached and asks the user to hit send to “confirm” they’re human. One tap is built to trigger several messages in sequence, sometimes to over a dozen numbers, sometimes to as many as 60. Some versions hijack the phone’s back button, so backing out isn’t as simple as it looks.
Each of those texts is a small charge to an international number the attackers lease. Together, a single visit can run up around $30. Because international SMS billing lags, the charge doesn’t show up until the next statement, weeks after anyone remembers the CAPTCHA that supposedly proved they weren’t a robot.
Why this is a training gap, not a phone bill
Thirty dollars on a phone bill is not the firm’s exposure here. The reflex is.
Your trust account already runs on a rule like this: no single signature moves money, no matter how routine the request looks, because a request that looks routine is exactly the moment people stop checking. This scam is testing the same reflex outside the trust account, on a device most firms have never thought to put that discipline around.
The person who taps send on an unread text because a webpage told them to is the same person who won’t pause on a spoofed e-filing confirmation, a fake DocuSign envelope waiting on a client signature, or a login push that looks like it’s coming from Clio. None of those cost thirty dollars. They cost client files, matter deadlines, and in the worst case, trust account credentials.
It’s the duty of competence and confidentiality that’s at stake here, framed under ABA Model Rule 1.6(c) as making reasonable efforts to prevent unauthorized disclosure, and Comment 18 ties that duty directly to how well the people at your firm understand the technology they use every day. California firms carry a comparable obligation through Rule 1.1’s competence standard and Business and Professions Code section 6068(e), even though the rule structure isn’t identical to the ABA’s. Either way, reasonable efforts has to include staff who can tell a real verification prompt from a fake one, and a cyber insurance renewal asking about security awareness training will want to see exactly that.
What to tell your staff
The fix doesn’t need a training budget or a new policy. It’s one sentence: a CAPTCHA will never ask anyone to send a text message. If one does, close the page.
That’s worth two minutes at your next staff meeting, or one line added to whatever security awareness training the firm already runs. It’s also worth asking whether the firm’s network has any filtering on it, since these redirects often ride in through malicious ad networks and compromised sites that a paralegal can land on during completely normal browsing, doing nothing wrong.
Back to where this started. Could your staff, today, tell the difference between a routine verification prompt and this one? If the honest answer is closer to “probably not” than “yes,” that’s the gap worth closing. We help firms build the kind of staff training and network filtering that catches this, and document what that duty looks like in practice, before a client, an insurer, or opposing counsel is the one asking the question.


