EN
BREAKING AND SECURING TEXT-BASED CAPTCHAS: AN EMPIRICAL STUDY ON BANKS' ONLINE AUTHENTICATION SYSTEMS
Abstract
Digital transformation has made online banking services essential, increasing the need for strong security to protect sensitive user data. To distinguish human users from automated bots, banks often use CAPTCHA systems. This study evaluates the security of text-based CAPTCHAs used by Turkish banks in their online authentication processes, recognizing that user-friendliness is crucial for customer satisfaction in e-banking, alongside robust security. We analyzed 360 CAPTCHAs collected from 18 banks, assessing their security and vulnerability features using Optical Character Recognition (OCR)-based attack techniques. A custom-built CAPTCHA Resolver application was developed to automate CAPTCHA solving through systematic image filtering and processing prior to OCR. Experimental results reveal significant variation in security effectiveness across banks, with average OCR success rates ranging approximately from 53% to 98%, and the number of fully solved CAPTCHAs (100% accuracy) varying between 0 and 18 out of 20 samples per bank. The findings demonstrate that security features such as overlapping or connected characters, distortion, warping, rotation, and noisy or textured backgrounds are the most effective mechanisms for reducing OCR success. In contrast, vulnerability features, including single-type character usage (only uppercase, only lowercase, or only numbers), aligned characters, constant backgrounds, and binary color schemes, were identified as the dominant factors facilitating automated decoding. Overall, the results show that the presence of vulnerability features can outweigh the effect of multiple security mechanisms, indicating that increasing the number of security features alone does not necessarily guarantee CAPTCHA robustness. These findings underscore the critical need to balance strong security measures with usability and provide practical recommendations for improving text-based CAPTCHA design in banking applications to better protect against automated bot attacks while maintaining a user-friendly e-banking experience.
Keywords
Supporting Institution
This research received no specific grant from funding agencies in the public, commercial, or not-for-profit sectors.
Ethical Statement
Authors follow all ethical guidelines including authorship, citation, data reporting, and publishing original research
References
- L. Von Ahn, M. Blum, N. J. Hopper, and J. Langford, "CAPTCHA: Using Hard AI Problems for Security", in Proc. Advances in Cryptology — EUROCRYPT 2003, vol. 2656, E. Biham, Ed., in Lecture Notes in Computer Science, vol. 2656. Berlin, Heidelberg: Springer Berlin Heidelberg, 2003, pp. 294–311. doi: 10.1007/3-540-39200-9_18.
- G. Mori and J. Malik, "Recognizing objects in adversarial clutter: breaking a visual CAPTCHA", in Proc. IEEE Computer Society Conference on Computer Vision and Pattern Recognition, 2003. Proceedings., Madison, WI, USA: IEEE Comput. Soc, 2003, p. I-134-I–141. doi: 10.1109/CVPR.2003.1211347.
- J. Tam, J. Simsa, S. Hyde, and L. Ahn, "Breaking audio captchas", Advances in Neural Information Processing Systems, vol. 21, 2008, [Online]. Available: https://proceedings.neurips.cc/paper_files/paper/2008/hash/12092a75caa75e4644fd2869f0b6c45a-Abstract.html [Accessed: Mar. 24, 2025]
- P. Wang, H. Gao, X. Guo, Z. Yuan, and J. Nian, ‘Improving the Security of Audio CAPTCHAs With Adversarial Examples’, IEEE Trans. Dependable and Secure Comput., vol. 21, no. 2, pp. 650–667, Mar. 2024, doi: 10.1109/TDSC.2023.3236367.
- E. Bursztein, M. Martin, and J. Mitchell, ‘Text-based CAPTCHA strengths and weaknesses’, in Proceedings of the 18th ACM conference on Computer and communications security, Chicago Illinois USA: ACM, pp. 125–138, Oct. 2011. doi: 10.1145/2046707.2046724.
- I. Goodfellow, Y. Bengio, A. Courville, and Y. Bengio, Deep learning, vol. 1, no. 2. MIT press Cambridge, 2016. A. Acien, A. Morales, J. Fierrez, R. Vera-Rodriguez, and O. Delgado-Mohatar, ‘BeCAPTCHA: Behavioral bot detection using touchscreen and mobile sensors benchmarked on HuMIdb’, Engineering Applications of Artificial Intelligence, vol. 98, p. 104058, Feb. 2021, doi: 10.1016/j.engappai.2020.104058.
- S. A. Alsuhibany, ‘A Survey on Adversarial Perturbations and Attacks on CAPTCHAs’, Applied Sciences, vol. 13, no. 7, p. 4602, Apr. 2023, doi: 10.3390/app13074602.
- J. Wang, J. Qin, X. Xiang, Y. Tan, N. Pan, , "CAPTCHA recognition based on deep convolutional neural network", Mathematical Biosciences and Engineering, vol. 16, no. 5, pp. 5851–5861, 2019, doi: 10.3934/mbe.2019292.
Details
Primary Language
English
Subjects
System and Network Security
Journal Section
Research Article
Publication Date
September 2, 2026
Submission Date
December 11, 2025
Acceptance Date
February 23, 2026
Published in Issue
Year 2026 Volume: 14 Number: 3
APA
Ceran, O., Özdaş, M. B., & Tekin, U. (2026). BREAKING AND SECURING TEXT-BASED CAPTCHAS: AN EMPIRICAL STUDY ON BANKS’ ONLINE AUTHENTICATION SYSTEMS. Konya Journal of Engineering Sciences, 14(3), 1694-1722. https://doi.org/10.36306/konjes.1840529
AMA
1.Ceran O, Özdaş MB, Tekin U. BREAKING AND SECURING TEXT-BASED CAPTCHAS: AN EMPIRICAL STUDY ON BANKS’ ONLINE AUTHENTICATION SYSTEMS. KONJES. 2026;14(3):1694-1722. doi:10.36306/konjes.1840529
Chicago
Ceran, Onur, Mehmet Batuhan Özdaş, and Uğur Tekin. 2026. “BREAKING AND SECURING TEXT-BASED CAPTCHAS: AN EMPIRICAL STUDY ON BANKS’ ONLINE AUTHENTICATION SYSTEMS”. Konya Journal of Engineering Sciences 14 (3): 1694-1722. https://doi.org/10.36306/konjes.1840529.
EndNote
Ceran O, Özdaş MB, Tekin U (September 1, 2026) BREAKING AND SECURING TEXT-BASED CAPTCHAS: AN EMPIRICAL STUDY ON BANKS’ ONLINE AUTHENTICATION SYSTEMS. Konya Journal of Engineering Sciences 14 3 1694–1722.
IEEE
[1]O. Ceran, M. B. Özdaş, and U. Tekin, “BREAKING AND SECURING TEXT-BASED CAPTCHAS: AN EMPIRICAL STUDY ON BANKS’ ONLINE AUTHENTICATION SYSTEMS”, KONJES, vol. 14, no. 3, pp. 1694–1722, Sept. 2026, doi: 10.36306/konjes.1840529.
ISNAD
Ceran, Onur - Özdaş, Mehmet Batuhan - Tekin, Uğur. “BREAKING AND SECURING TEXT-BASED CAPTCHAS: AN EMPIRICAL STUDY ON BANKS’ ONLINE AUTHENTICATION SYSTEMS”. Konya Journal of Engineering Sciences 14/3 (September 1, 2026): 1694-1722. https://doi.org/10.36306/konjes.1840529.
JAMA
1.Ceran O, Özdaş MB, Tekin U. BREAKING AND SECURING TEXT-BASED CAPTCHAS: AN EMPIRICAL STUDY ON BANKS’ ONLINE AUTHENTICATION SYSTEMS. KONJES. 2026;14:1694–1722.
MLA
Ceran, Onur, et al. “BREAKING AND SECURING TEXT-BASED CAPTCHAS: AN EMPIRICAL STUDY ON BANKS’ ONLINE AUTHENTICATION SYSTEMS”. Konya Journal of Engineering Sciences, vol. 14, no. 3, Sept. 2026, pp. 1694-22, doi:10.36306/konjes.1840529.
Vancouver
1.Onur Ceran, Mehmet Batuhan Özdaş, Uğur Tekin. BREAKING AND SECURING TEXT-BASED CAPTCHAS: AN EMPIRICAL STUDY ON BANKS’ ONLINE AUTHENTICATION SYSTEMS. KONJES. 2026 Sep. 1;14(3):1694-722. doi:10.36306/konjes.1840529