Cybercrime as a Service Fuels New Scam Waves

Help Net Security · Medium sophistication
Last updated August 1, 2026

A threat landscape report describes how criminals now buy or rent phishing, fraud, malware, and hidden infrastructure “as a service,” making scams faster to launch and harder to stop. The article highlights practical, repeatable social-engineering workflows such as fake CAPTCHA pages that trick users into costly actions, and browser push-notification scams that create a persistent channel for fraud messages.

How the attack worked

A threat landscape report describes how cybercrime capabilities are increasingly sold or rented as services, allowing even low-skilled actors to operate at scale with anonymity and short-lived infrastructure. Two repeatable web-based scams stand out. The first uses a fake CAPTCHA or human-verification page that tricks mobile users into taking an action that triggers costly international text messages, with one observed case generating about 60 messages and roughly $30 in charges. The second uses a similar fake verification, cookie banner, or CAPTCHA prompt to get users to click Allow on browser notifications. Once granted, that permission becomes a persistent channel attackers use to flood victims with scam notifications, in some cases more than 140 per day promoting investment scams, gambling sites, fake antivirus alerts, and government impersonation content.

Why it succeeded

These scams work because they exploit routine, low-friction interactions that people rarely question: clicking through a CAPTCHA or approving a notification permission. Attackers also build lookalike lure pages that replicate branding, logos, and user experience closely enough that victims trust them without checking the underlying domain. AI is also being used to automate reconnaissance and generate more convincing lures, while cloaking, redirect chains, and fast domain rotation, with some phishing pages lasting under 24 hours, make detection and takedown harder.

What to watch for

  • A CAPTCHA or verification step that unexpectedly triggers messaging activity or unusual charges
  • A site demanding notification permissions as a condition for viewing content
  • A sudden flood of notifications after granting Allow
  • Lookalike login or verification pages reached through unexpected links
  • Requests for OTPs, device fingerprints, or biometric data through a verification flow

How to build resistance

  • Treat unexpected CAPTCHA or verification prompts as suspicious, especially if they trigger messaging or app-level actions
  • Avoid clicking Allow on notification prompts unless there is a clear, expected business reason
  • Train staff to verify link sources and domains rather than trusting logos or page design alone
  • Give extra attention to executives, finance, and customer support roles, since these groups face targeted impersonation, BEC attempts, and OTP or credential harvesting
  • Reinforce that legitimate verification steps rarely require sending messages, granting broad permissions, or entering one-time passwords on unfamiliar pages

Key findings

  • Cybercrime capabilities are increasingly “buy/rent” services, helping even low-skilled actors operate at scale with anonymity and short-lived infrastructure.
  • AI is being used to automate reconnaissance and generate more convincing lures.
  • Executives are specifically at risk from impersonation fraud and business email compromise (BEC).
  • Fake CAPTCHA pages can manipulate mobile users into costly actions; one observed case generated about 60 international messages costing about $30.
  • Browser push-notification scams trick users into clicking “Allow,” then bombard them with persistent scam notifications (reported as 140+ per day in some cases).
  • Attackers use cloaking, redirect chains, and “bulletproof hosting” to hide campaigns and quickly rotate domains/URLs, some phishing pages last under 24 hours.
  • Attackers can take over trusted subdomains via dangling CNAME records and use them for phishing or malware delivery.
  • Software supply-chain compromises (e.g., TeamPCP) can create downstream opportunities to steal credentials and spread malicious code.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, Customer Support, IT / Security, Developers / DevOps.
  • Affected industries: Finance and digital banking, Telecommunications, Technology / Cloud services, Software development and DevOps, Consumers / general public.
  • Attack channels: website.
  • Impersonated: A generic “human verification” or CAPTCHA provider (no specific brand named), A website’s “verification” / “cookie consent” flow (no specific brand named), Impersonated entities on a lookalike lure page (specific brands not named).

Red flags to watch for

  • A CAPTCHA/verification step that unexpectedly triggers messaging activity
  • Unclear reason for “human verification” on a page the user did not expect
  • Unexpected charges or rapid message-sending behavior after one click
  • A site demanding notification permissions to proceed
  • “Allow” is presented as a requirement for verification or content access
  • A sudden flood of spam notifications after permission is granted
  • Lookalike login pages reached via unexpected links
  • Requests for unusually broad access/data (contacts, biometrics)
  • Verification steps that go beyond normal banking/app behavior
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is cybercrime as a service?

It refers to criminals buying or renting phishing, fraud, malware, and hidden infrastructure as ready-made services, which lets even low-skilled actors run scams at scale with anonymity and short-lived infrastructure.

How do fake CAPTCHA scams work?

A fraudulent human-verification page tricks a mobile user into an action that triggers expensive international text messages, with one observed case generating about 60 messages costing about $30.

Why are browser push-notification prompts risky?

Clicking Allow on a fake CAPTCHA, cookie banner, or verification prompt gives attackers a persistent channel to the device, and some victims received more than 140 scam notifications per day.

Are executives specifically at risk?

Yes, executives are exploited in impersonation fraud, business email compromise, and other social engineering schemes because of their identities and access.

Read the video transcript

You tap a simple CAPTCHA on your phone… and 60 international texts go out, costing you thirty bucks. One tap. This is cybercrime-as-a-service: rented fake CAPTCHA pages and push-notification scams that look legit, then quietly send paid SMS or flood you with 140 scam alerts a day. Here’s the trick: criminals buy ready-made kits that clone real sites, rotate domains every day, and use fake CAPTCHAs or cookie banners to make you tap Verify or Allow without thinking. Your move: if a CAPTCHA or verification makes your device send messages or asks to turn on notifications, stop and close the page, don’t tap Allow, don’t tap Verify.

Similar attacks

Hijacked Hotel Wi‑Fi Serves Fake Updates

Hijacked Hotel Wi‑Fi Serves Fake Updates

Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into…

August 1, 2026