Hackers Use Hijacked University Emails to Scam Students, Pose as FBI Agent
Hackers use compromised university emails for fake job offers and gift card scams.
Summary
Proofpoint has identified a scam campaign where threat actors compromise university email accounts to send fake job offers to students and staff. The attackers first steal credentials using phishing forms hosted on legitimate services, then use the compromised accounts to distribute fraudulent job opportunities. The scam escalates to advance-fee fraud, where victims are sent fraudulent checks and instructed to purchase gift cards with the proceeds, with some impersonating FBI agents.
Full text
Security Cyber Crime Scams and FraudHackers Use Hijacked University Emails to Scam Students, Pose as FBI Agent Students, job seekers and university staff, watch out for fake job offers sent from legitimate university email accounts. byDeeba AhmedSeptember 29, 20262 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening Proofpoint uncovers hackers using compromised university accounts to send fake job offers, steal credentials, and run gift card scams, including FBI impersonation. Cybercriminals are targeting university students with fake employment opportunities sent from compromised higher education email accounts. Research shared with Hackread.com by Proofpoint shows a multi-stage attack chain that starts with credential theft and can lead to account takeover (ATO) and advance-fee fraud (AFF). Fake Account Warnings Steal University Credentials The campaigns begin with emails warning students, staff, or alumni that their university account is due to be deactivated because of retirement, graduation, or transfer. Recipients are sent to credential-harvesting forms hosted on legitimate services including Google Forms, Microsoft Office, Wix, Jotform, and Zoho Forms. To get around form restrictions on password collection, some pages avoided the word “password” and told victims to enter it under a field labelled “WORDWORD.” The forms also collect personally identifiable information (PII), including legal names, phone numbers, university email addresses, and personal email addresses. Compromised Accounts Deliver Fake Job Offers Once credentials are obtained, attackers use compromised university accounts to distribute fake job and internship offers. Proofpoint observed roles including remote personal assistants, secret shoppers, charity workers, and research assistants. The compromised accounts were used to send the offers both within the affected universities and to external recipients. Example of a fraudulent remote personal assistant job offer used in the campaign. (Credit: Proofpoint) According to Proofpoint’s report, its researchers engaged with the fraudsters to examine how they made money. After asking for a resume and checking whether the target had mobile banking and access to a printer, the scammers sent fraudulent checks averaging about $1,000. Victims were told to deposit the check, keep part as pay, and use the remainder to buy $100 gift cards before sending the codes back. When researchers refused to send the money, the scammers escalated to repeated calls, text messages, and threats. In one case, a fraudster impersonated an FBI agent using the name “Agent Dozier Jr.” Scammer impersonating an FBI agent using the name “Agent Dozier Jr.” (Credit: Proofpoint) Researchers sent tracking links to the threat actors during their investigation. The resulting IP data indicated that the attackers were operating from mobile networks in Nigeria. Proofpoint said this aligns with the Nigerian links it commonly observes in advance-fee fraud operations. The Wider Risk Similar recruitment scams have targeted job seekers outside universities. Hackread.com has reported several recruitment scams in recent years, including a May 2025 Netcraft investigation into fake technology-company jobs that pushed victims into advance-fee schemes involving cryptocurrency. More recently, the RecruitTrap campaign used more than 3,000 phishing URLs impersonating recruitment processes across over 50 organizations, including Amazon, Apple, Boeing, Deloitte, and Lego, to steal corporate credentials. The Proofpoint campaign shows how these tactics become more effective when attackers first compromise a trusted university account. Proofpoint notes that MFA can prevent this type of ATO when attackers only have the stolen username and password. Universities should, therefore, enforce MFA, while students should independently verify unexpected job offers and never send money or gift cards to an alleged employer. (Photo by Kirill Dice on Unsplash) Deeba Ahmed Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage. View Posts Cyber CrimeCybersecurityFraudJob ScamPhishingRecruitmentScam Leave a Reply Cancel reply View Comments (0) Related Posts Read More Artificial Intelligence Cyber Attacks Security Chinese State Hackers Jailbroke Claude AI Code for Automated Breaches Anthropic, the developer behind Claude AI, says a Chinese state sponsored group used its model to automate most of a cyber espionage operation against about 30 companies with Claude handling up to 90% of the technical work. byDeeba Ahmed Read More Security Malware Malware called InnfiRAT is creeping into cryptocurrency wallets Dubbed InnfiRAT; the malware can also steal browser cookies resulting in a compromise of sensitive data such as usernames and passwords. bySudais Asif Read More Security Leaks Voters’ Database of 2.9 Million State of Louisiana Natives Leaked Online 2.9 Million voters’ data means the entire State of Louisiana — It shows how vulnerable the US cyber… byWaqas Read More Cyber Crime Hackers illegally selling stolen Fortnite accounts & botnets on Instagram It is not happening on Dark Web but Instagram. Instagram has become much more than a platform to… byWaqas