Graphical user authentication (GUA) is an alternative replacement for traditional password that used text-based form. Even though GUA has high usability and security, it is also facing security attacks that legitimate from the traditional password such as brute force, shoulder surfing, dictionary attack, social engineering, and guessing attacks. The proposed category-based graphical user authentication (CGUA) scheme is developed for web application and based on image category. This category image is inspired from the Hanafuda Japanese card game. The scheme also involved several security features such as decoys, randomly assigned, hashing, limited login attempts, and random characters to strengthen the CGUA scheme. Overall, the proposed CGUA scheme was able to mitigate known attacks based on the security features analysis.