Fake CAPTCHA Trick Tied to Berlin Gov Data Leak

The Record · Medium sophistication
Last updated September 8, 2026

Berlin authorities are investigating a new release of stolen government data, including published login credentials. Germany’s cyber agency also warned of a related campaign where attackers compromise websites and use fake CAPTCHA pages to trick visitors into running malicious commands, enabling data theft and ransomware.

How the Attack Worked

According to reporting reviewed by Germany's Federal Office for Information Security (BSI), attackers compromised legitimate websites and inserted fake CAPTCHA verification pages. Instead of the usual click-to-verify checkbox, these fake pages instructed visitors to manually copy and run a command on their own computer to "complete verification." That single action gave attackers a foothold, enabling both data theft and, in some cases, ransomware deployment.

This technique matters because it shifts the attack from a technical exploit to a social engineering trick. The malicious code never has to bypass browser security controls because the victim runs it themselves, believing they are completing a routine step.

Why It Succeeded

CAPTCHA prompts are so common that most users no longer question them. The fake page exploited that familiarity, adding one small but critical deviation from normal since users are asked to open a command window or paste text rather than simply click a box. Because the sites involved were already compromised, the prompts appeared in a context users trusted, making the unusual instruction seem like a plausible extra step rather than an obvious red flag.

BSI also noted that this campaign, alongside the separate Berlin government data release, involved both theft and encryption in the same operation. Combining data theft with ransomware increases pressure on victims, since attackers can threaten to publish stolen data even if backups allow recovery from encryption.

What to Watch For

  • A CAPTCHA page asking you to run commands is not normal behavior for a verification step
  • Instructions that require copying or pasting text into a terminal or run dialog, rather than clicking a checkbox
  • Verification prompts appearing on a site that never asked for them before
  • Login credentials appearing in leaked data dumps, even without confirmation of which systems they unlock

Building Resistance

Organizations across government, education, and healthcare should treat this pattern as a training priority for all staff, not just IT teams. Practical steps include:

  • Teaching employees to stop and report any prompt asking them to run commands, regardless of how official the page looks
  • Building incident response workflows that assume ransomware incidents may include data theft, prioritizing rapid containment and notification
  • Resetting passwords and reviewing access quickly whenever credentials may have been exposed, even before confirming which systems are affected
  • Reinforcing that legitimate CAPTCHA checks never require manually executing code

The Berlin case shows how a straightforward social engineering trick, paired with the possibility of stolen credentials being reused elsewhere, can create risk well beyond the original target.

Key findings

  • Hackers published stolen Berlin government data that included login credentials.
  • Data stolen from two Berlin ministries may include personal information about public employees and possibly residents (names, addresses, bank info, emails, phone numbers, and documents).
  • BSI warned about a campaign resembling “TerminalFix,” where compromised websites show fake CAPTCHA pages that trick users into manually running malicious commands.
  • BSI said the campaign attempts both data theft and ransomware deployment, leveraging pressure via threatened publication of stolen information.
  • Rhysida claimed responsibility for the earlier breach and claimed theft of 5.79 TB, but Berlin has not publicly attributed the incident or verified the claims.

Who’s being targeted

  • Commonly targeted roles: All employees, Public-facing staff, IT/helpdesk, Security team, Leadership/incident response.
  • Affected industries: Government / Public Administration, Education, Healthcare.
  • Attack channels: website.
  • Impersonated: CAPTCHA / website security verification page.

Red flags to watch for

  • A CAPTCHA page asking you to run commands is not normal
  • Instructions require copying/pasting commands into the computer rather than clicking a standard verification checkbox
  • Unexpected verification prompts on a site that previously didn’t require them
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the fake CAPTCHA attack described in the Berlin case?

Attackers compromised websites and displayed fake CAPTCHA verification pages that instructed visitors to manually copy and run malicious commands on their own computers, enabling data theft and ransomware deployment.

What data was exposed in the Berlin government leak?

Hackers published stolen data from two Berlin ministries, including login credentials and potentially personal information such as names, addresses, bank details, emails, phone numbers, and documents belonging to public employees and possibly residents.

Why do ransomware groups combine data theft with encryption?

Germany's BSI reported that attackers in this campaign attempted both to steal data and install ransomware, using the threat of publishing stolen information as additional pressure on victims.

How can employees spot a fake CAPTCHA scam?

Any CAPTCHA or verification prompt that asks a user to copy and paste or manually run a command is abnormal, since standard CAPTCHAs only require a click, and such requests should be reported to IT or security immediately.

Read the video transcript

In Berlin, stolen government logins led to data leaks and ransomware. The twist? It all started with a fake CAPTCHA. Hackers compromised real websites and popped up a fake CAPTCHA page. It told visitors: copy this command and run it on your computer to verify access. Real CAPTCHAs make you click a box or pick traffic lights. They never tell you to paste commands. That trick let them steal data and try to install ransomware, then threaten to leak what they stole. If any website or CAPTCHA tells you to copy, paste, or run a command, stop immediately and report it to IT or security. That one pause can stop the next Berlin-style leak.

Similar attacks

Fake CAPTCHA “Fix” Tricks Users Into Running Malware

Fake CAPTCHA “Fix” Tricks Users Into Running Malware

Multiple real-world intrusions used a ClickFix-style lure where victims visiting compromised websites saw fake CAPTCHA prompts and were tricked into running a command themselves. Separately, attackers also abused the legitimate, signed Node.js runtime (node.exe) to run malicious JavaScript while…

September 3, 2026
Fake CAPTCHA “Copy/Paste” Sites Push CastleLoader

Fake CAPTCHA “Copy/Paste” Sites Push CastleLoader

Threat actors are using fake CAPTCHA pages on compromised or lookalike websites to trick people into copying and pasting malicious commands (“paste and run”). The article describes real campaigns tied to CastleLoader and similar activity, including fake background-removal sites and job-site…

July 23, 2026
Fake CAPTCHA ‘ClickFix’ Drops Cruciferra Malware

Fake CAPTCHA ‘ClickFix’ Drops Cruciferra Malware

A real malware campaign used compromised websites to show fake CAPTCHA/verification pages that tricked people into copying and running a PowerShell command themselves. That manual “copy/paste” step helped the attackers bypass normal download defenses and install the Cruciferra loader, which then…

August 25, 2026
Sandworm Uses Fake CAPTCHAs to Spread Malware

Sandworm Uses Fake CAPTCHAs to Spread Malware

Ukraine’s CERT says the Russia-linked Sandworm group is tricking targets into infecting their own PCs using compromised websites that display fake CAPTCHA checks. Victims are instructed to copy and paste a PowerShell command, which downloads malware and can lead to deeper compromise. CERT also…

July 16, 2026
Fake CAPTCHA Tricks Users Into Running Malware

Fake CAPTCHA Tricks Users Into Running Malware

Researchers found a criminal operation (StopAndProtect) that used nearly 2,000 hacked WordPress sites as a delivery network. Visitors were shown a fake CAPTCHA that pressured them to copy and run a PowerShell command, which then installed malware that could steal data, capture screenshots, and…

August 20, 2026
Fake CAPTCHA on Hacked WordPress Spreads Malware

Fake CAPTCHA on Hacked WordPress Spreads Malware

Researchers described a real cybercrime operation (“StopAndProtect”) that compromised nearly 2,000 WordPress sites and used them to show fake CAPTCHA pages that trick visitors into running malicious commands. Victims can end up with malware that steals files and screenshots and, in some cases,…

August 19, 2026